Table of Contents
IriusRisk Team
IriusRisk Team
|
The Threat Modeling Experts
October 13, 2022

Product Update: Release 4.8 - Featuring New Compenents

Product Update: Release 4.8

We are excited to announce the release of IriusRisk 4.8 which includes:

  • New components
  • Bi-directional dataflows for Visio
  • Security Improvements

Security Content

fba1993c-e64f-4001-9364-5536ce46fa0d

The following new components have been added to IriusRisk:

  • Google Cloud Identity and Access Management (IAM)
  • Google Cloud Identity-Aware Proxy (IAP)
  • Google Cloud Terraform
  • Google Cloud Router
  • Google Cloud Interconnect
  • Google Vertex AI
  • Google Vertex AI Workbench
  • Google Cloud Functions
  • SSH Client
  • SSH Server

Visio API

e84458f5-e5c9-4c32-9565-2bd2e013635e

The Visio import API will now parse bi-directional dataflows in Visio diagrams and create the two uni-directional dataflows used in IriusRisk.

Security improvements

At the beginning of April this year we sent an email informing customers of the vulnerability CVE-2022-22965 in the Spring framework version 4.3.23 used by IriusRisk. SaaS and on-premise customers with default docker configurations were not vulnerable due to mitigating controls in place. The version of Grails used meant we were not able to immediately upgrade to the patched Spring 5.x version. Although not exploitable, we did not want vulnerable libraries to remain in the product long term.

In this release we have completely removed Grails and have upgraded Spring to the non-vulnerable version 5.3.21. We have also fixed two additional critical vulnerabilities with the migration:

  • CVE-2022-22978, relating to spring security
  • CVE-2022-35912 relating to grails core

Release notes

For more information, see the Version 4.8 Release Notes.

Shape the future of Threat Modeling with us!

Join IriusRisk Horizon

IriusRisk Horizon - Customer Research, Product Discovery, and Early Access

Logos of the European Union with text 'Funded by the European Union NextGenerationEU', the Spanish Government Ministry of Economic Affairs and Digital Transformation, red.es, and the Plan de Recuperación, Transformación y Resiliencia.

FAQs

keyboard_arrow_down

keyboard_arrow_down

keyboard_arrow_down

keyboard_arrow_down

keyboard_arrow_down
About the author...

IriusRisk Team

The Threat Modeling Experts
IriusRisk
The IriusRisk Team represents the collective expertise and official voice of the company, driven by security researchers, product managers, and engineering leaders dedicated to the automation of threat modeling. This content is curated by the company's core staff to deliver official news, product roadmaps, and feature updates. The team's mission is to ensure every release and announcement is delivered with transparency, technical accuracy, and strategic alignment with the Secure by Design philosophy.