Dear Axon Ivy Users,
We want to inform you that we have fixed the following security vulnerabilities:
- XIVY-19126 Potential remote code execution via workflow API — Severity: HIGH
- XIVY-19142 Potential remote code execution via process start — Severity: CRITICAL
These issues were reported responsibly through our Bug Bounty Program; we thank the reporter for bringing them to our attention.
We strongly recommend that you update your Axon Ivy Engines to the latest Update Release of your LTS version as soon as possible to mitigate any risk.
The following LTS versions are affected:
- 10.0.0 - 10.0.37
- 12.0.0 - 12.0.15
The issues are fixed in the following LTS versions:
If you need assistance with the update or have questions, please contact your Axon Ivy support representative.
We apologize for any inconvenience this may have caused and appreciate your cooperation.
Kind regards,
Axon Ivy Product Development