projectdoc Toolbox 7.4.1 Release Notes

Security fix for CVE issue with dependency.

Release Date

Today we released version 7.4.1 of the projectdoc Toolbox!

The projectdoc Toolbox is an add-on for Confluence supporting agile software development teams to collaborate on process, project, system, and product documentation. 

New and Noteworthy

This release provides the following new and noteworthy features.

CVE-2025-48924

The app uses the platform dependency to commons-lang in a version that has been reported vulnerable to CVE-2025-48924.

For detailed information, please refer to https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1.

The vulnerability is reported to be fixed in 3.18.0. This version updates this dependency.

Installation Instructions

Install the projectdoc Toolbox to your Confluence instance.

There are no additional steps necessary.

Upgrade Instructions

Update the projectdoc Toolbox on your Confluence instance.

This version supports Confluence version 9.2.x. and later.

For previous versions of Confluence there are separate versions of the projectdoc Toolbox:

  • Confluence 8.x/7.x see version 6.2.15
  • For Confluence 9.0.x and 9.1.x we recommend to upgrade to Confluence 9.2.x (LTS)

List of Changes

The following changes are part of version 7.4.1 of the projectdoc Toolbox for Confluence

Key Summary T P Description
PDAC-1859 CVE-2025-48924 affects pkg:maven/org.apache.commons/commons-lang3@3.17.0 Bug Blocker (migrated)

The projectdoc Toobox for Confluence app uses the platform dependency to commons-lang in a version that has been reported vulnerable to CVE-2025-48924.

For detailed information, please refer to https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1.

The vulnerability is reported to be fixed in 3.18.0 and above.

PDAC-1860 Dark Theme Support for Swagger UI Improvement Major

Make the Swagger UI integration respond to the Confluence Dark Theme feature.

Related Releases

This version does not require updates of of the Web API Extension or the Information Systems Extension, but it does require the update of the Doctype Add-ons to the versions shown below.

Extension Add-ons

Doctype Add-on Version
13.1.1
8.0.1

Web API Extension

The following changes are part of the latest Web API Extension.

Key Summary T P Status Resolution Description
PDEXWAPI-90 Dark Theme Support for Swagger UI Improvement Major Done Fixed

Make the Swagger UI integration respond to the Confluence Dark Theme feature.

PDEXWAPI-89 CVE-2025-48924 affects pkg:maven/org.apache.commons/commons-lang3@3.17.0 Bug Blocker (migrated) Done Fixed

The Web API Extension uses the platform dependency to commons-lang in a version that has been reported vulnerable to CVE-2025-48924.

For detailed information, please refer to https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1.

The vulnerability is reported to be fixed in 3.18.0 and above.

Information Systems Extension

The following changes are part of the latest Information Systems Extension.

Key Summary T P Status Resolution Description
PDEXINFOSY-56 Update to Confluence Latest Releases Improvement Major Done Fixed

Update dependencies to the latest Confluence 9.2.6 and support for Confluence 9.5.2.

Update Swagger dependencies to the latest versions.

Update AMPS and dependency checks to latest version.

PDEXINFOSY-57 CVE-2025-48924 affects pkg:maven/org.apache.commons/commons-lang3@3.17.0 Bug Blocker (migrated) Done Fixed

The Information Systems Extension uses the platform dependency to commons-lang in a version that has been reported vulnerable to CVE-2025-48924.

For detailed information, please refer to https://lists.apache.org/thread/bgv0lpswokgol11tloxnjfzdl7yrc1g1.

The vulnerability is reported to be fixed in 3.18.0 and above.

References

Links to information referenced in the release notes.

projectdoc Rebuild Manual
Information for administrators on how to maintain projectdoc documents or to build them from scratch.

Resources

Additional resources on our website regarding the release of the projectdoc Toolbox.

Release Notes for the projectdoc Toolbox
Relevant information on changes to the projectdoc Toolbox for Confluence introduces by new versions of this app.
Glossary
Terms used in and defined for projectdoc.
FAQs
Questions and answers related to the projectdoc Toolbox and Confluence.