Skip to content

Bundled Java runtime in BEAST 2.7.x releases has known vulnerabilities #1215

Description

@berkleycam

Hi BEAST team,

The Java runtime bundled with several BEAST 2.7.x Linux x86 release packages is out of date and has been flagged for known serious security vulnerabilities.

I verified that the BEAST v2.7.3 through v2.7.7 release packages include the vulnerable Azul Zulu Java 17.0.3:

BEAST.v2.7.3.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.4.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.5.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.6.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.7.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3

Please see:
April 2025 Quarterly Update Release Notes

Those release notes include security fixes for Zulu 17 in the 17.57.x line and list the following CVEs among the fixed vulnerabilities:

CVE-2024-47606
CVE-2024-54534
CVE-2025-21587
CVE-2025-30691
CVE-2025-30698

Could you advise on the recommended way to address this for BEAST 2.7.x installations?

Specifically, is replacing the bundled jre directory with a current Java 17 runtime supported, or is there a recommended process for rebuilding the BEAST release package with an updated bundled Java runtime?

If replacing the bundled jre directory is supported, do you have a recommended Java 17 runtime/version for BEAST 2.7.x?

Much thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions