Skip to main content

Security Advisories

These articles record how Hannon Hill assessed a published vulnerability against Cascade CMS — what the issue is, whether Cascade Cloud and on-premise installations are affected, and any action an administrator needs to take. Most entries conclude that Cascade CMS is not affected; the ones that require action say so at the top of the article.

Reporting a vulnerability

If you believe you've found a security issue in Cascade CMS, contact our support team directly rather than filing it publicly.

Advisories requiring action

Tomcat and Spring

Log4j