Upgrade NOW: TDS 5.4-SNAPSHOT to address Spring4Shell CVE

All releases of TDS 5 prior to the March 31, 2022 TDS 5.4-SNAPSHOT release are vulnerable to the Spring Framework library Spring4Shell exploit [cve-2022-22965].

We are aware of active hacking attempts against Internet-based unpatched TDS servers, with one reported successful attempt in the community. Such attempts occurred as early as Wednesday March 30 before Spring officially announced the existence of the vulnerability.

If you haven't done so already, we strongly encourage 5.x users to upgrade to the latest snapshot immediately.

[Read More]

TDS version 4.6.20 released

The THREDDS development team released version 4.6.20 of the TDS on February 16th, 2022. This release contains various upgrades to third party libraries that address security exploits, as well as a bug fix in the WMS service. You can find the full release notes here.

Note: The TDS downloads page has moved! You can now find TDS jar files at https://downloads.unidata.ucar.edu/tds/

For TDS 5.x users - the 5.4 release will be ready soon, but we are still working to address a number of reported bugs prior to the release date, which remains TBA. In the meantime, please continue to the SNAPSHOT release available on the TDS downloads page.

THREDDS Data Server Version 4.6.18 Released

The Unidata THREDDS Development Team released an updated version of the THREDDS Data Server (TDS) (and bundled netCDF-Java/Common Data Model (CDM) library) on December 10th, 2021. This release addresses a severe third party library security vulnerability. TDS 4.6.x administrators are encouraged to upgrade to version 4.6.18.

[Read More]

THREDDS Data Server version 5.2 Released

The THREDDS Data Server (TDS) version 5.2 release was announced on December 10th, 2021. This is a minor release that addresses a severe third party library security vulnerability.

[Read More]

TDS Users: Update Your Configuration Now

Users of the THREDDS Data Server (TDS) are strongly encouraged to update the configuration files on their servers as soon as possible, and before they next restart their servers. Changes in the UCAR/Unidata web infrastructure will cause Web Map Service (WMS) features provided by the TDS to behave incorrectly.

This change affects all versions of the TDS.

[Read More]
News@Unidata
News and information from the Unidata Program Center
News@Unidata
News and information from the Unidata Program Center

Welcome

FAQs

Developers’ blog

Recent Entries:
Take a poll!

What if we had an ongoing user poll in here?

Browse By Topic
  • feed Community (432)
Browse by Topic
« December 2024
SunMonTueWedThuFriSat
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
    
       
Today