Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tessera 22.10.0 is having vulnerabilities for libexpat, login and passwd libraries #1507

Open
rupesh-pithva opened this issue Dec 13, 2022 · 2 comments

Comments

@rupesh-pithva
Copy link

we are getting below vulnerabilities for latest tessera 22.10.0 image. Please let us know when the new image will be available with the fixes for this vulnerabilities.

image

@sushilsaha1111
Copy link

@antonydenyer Please see the details above. The latest Tessera image is showing some vulnerabilities

@rupesh-pithva
Copy link
Author

@antonydenyer there is another vulnerability raised for tessera image.

Please could you let us know when the new drop of the tessera image will be available with the fixes.
Details below:-
vulnerability name: - Java (Maven) Security Update for org.yaml:snakeyaml (GHSA-w37g-rhq8-7m4j)

Refer to Github security advisory GHSA-w37g-rhq8-7m4j for updates and patch information.
Patch:
Following are links for downloading patches to fix the vulnerabilities:

GHSA-w37g-rhq8-7m4j:org.yaml:snakeyaml

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants