Hi BEAST team,
The Java runtime bundled with several BEAST 2.7.x Linux x86 release packages is out of date and has been flagged for known serious security vulnerabilities.
I verified that the BEAST v2.7.3 through v2.7.7 release packages include the vulnerable Azul Zulu Java 17.0.3:
BEAST.v2.7.3.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.4.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.5.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.6.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.7.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
Please see:
April 2025 Quarterly Update Release Notes
Those release notes include security fixes for Zulu 17 in the 17.57.x line and list the following CVEs among the fixed vulnerabilities:
CVE-2024-47606
CVE-2024-54534
CVE-2025-21587
CVE-2025-30691
CVE-2025-30698
Could you advise on the recommended way to address this for BEAST 2.7.x installations?
Specifically, is replacing the bundled jre directory with a current Java 17 runtime supported, or is there a recommended process for rebuilding the BEAST release package with an updated bundled Java runtime?
If replacing the bundled jre directory is supported, do you have a recommended Java 17 runtime/version for BEAST 2.7.x?
Much thanks!
Hi BEAST team,
The Java runtime bundled with several BEAST 2.7.x Linux x86 release packages is out of date and has been flagged for known serious security vulnerabilities.
I verified that the BEAST v2.7.3 through v2.7.7 release packages include the vulnerable Azul Zulu Java 17.0.3:
BEAST.v2.7.3.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.4.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.5.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.6.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
BEAST.v2.7.7.Linux.x86.tgz — Zulu17.34+19-CA / Java 17.0.3
Please see:
April 2025 Quarterly Update Release Notes
Those release notes include security fixes for Zulu 17 in the 17.57.x line and list the following CVEs among the fixed vulnerabilities:
CVE-2024-47606
CVE-2024-54534
CVE-2025-21587
CVE-2025-30691
CVE-2025-30698
Could you advise on the recommended way to address this for BEAST 2.7.x installations?
Specifically, is replacing the bundled jre directory with a current Java 17 runtime supported, or is there a recommended process for rebuilding the BEAST release package with an updated bundled Java runtime?
If replacing the bundled jre directory is supported, do you have a recommended Java 17 runtime/version for BEAST 2.7.x?
Much thanks!