Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

thingsboard/3.8.1-r4: cve remediation #38041

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

thingsboard/3.8.1-r4: fix GHSA-mfj5-cf8g-g2fv

d9ecc89
Select commit
Loading
Failed to load commit list.
Open

thingsboard/3.8.1-r4: cve remediation #38041

thingsboard/3.8.1-r4: fix GHSA-mfj5-cf8g-g2fv
d9ecc89
Select commit
Loading
Failed to load commit list.
Octo STS / ci-cve-scan failed Dec 20, 2024 in 0s

CVE scan report

CVE scan report

Details

aarch64/thingsboard-3.8.1-r5.apk

✅ No vulnerabilities found

aarch64/thingsboard-tb-js-executor-3.8.1-r5.apk

✅ No vulnerabilities found

aarch64/thingsboard-tb-mqtt-transport-3.8.1-r5.apk

└── 📄 /usr/share/tb-mqtt-transport/bin/tb-mqtt-transport.jar
        📦 logback-core 1.5.5 (java-archive)
            Low CVE-2024-12801 GHSA-6v67-2wr5-gvf4 fixed in 1.15.13
            Medium CVE-2024-12798 GHSA-pr98-23f8-jwxv fixed in 1.15.13

aarch64/thingsboard-tb-node-3.8.1-r5.apk

└── 📄 /usr/share/thingsboard/bin/thingsboard.jar
        📦 logback-core 1.5.5 (java-archive)
            Low CVE-2024-12801 GHSA-6v67-2wr5-gvf4 fixed in 1.15.13
            Medium CVE-2024-12798 GHSA-pr98-23f8-jwxv fixed in 1.15.13

aarch64/thingsboard-tb-web-ui-3.8.1-r5.apk

✅ No vulnerabilities found

x86_64/thingsboard-3.8.1-r5.apk

✅ No vulnerabilities found

x86_64/thingsboard-tb-js-executor-3.8.1-r5.apk

✅ No vulnerabilities found

x86_64/thingsboard-tb-mqtt-transport-3.8.1-r5.apk

└── 📄 /usr/share/tb-mqtt-transport/bin/tb-mqtt-transport.jar
        📦 logback-core 1.5.5 (java-archive)
            Low CVE-2024-12801 GHSA-6v67-2wr5-gvf4 fixed in 1.15.13
            Medium CVE-2024-12798 GHSA-pr98-23f8-jwxv fixed in 1.15.13

x86_64/thingsboard-tb-node-3.8.1-r5.apk

└── 📄 /usr/share/thingsboard/bin/thingsboard.jar
        📦 logback-core 1.5.5 (java-archive)
            Low CVE-2024-12801 GHSA-6v67-2wr5-gvf4 fixed in 1.15.13
            Medium CVE-2024-12798 GHSA-pr98-23f8-jwxv fixed in 1.15.13

x86_64/thingsboard-tb-web-ui-3.8.1-r5.apk

✅ No vulnerabilities found