pentaho-platform icon indicating copy to clipboard operation
pentaho-platform copied to clipboard

Known Security Vulnerabilities to be fixed

Open dicaeffe opened this issue 4 years ago • 3 comments

Hello, version 9.0 (and uppers) of Pentaho has few known CVEs (Common Vulnerabilities and Exposures) due to its dependencies.

Is possible to fix those security issues by updating the versions reported below?

Apache Axis2/Java

Apache Log4j - log4j

jackson-databind

karaf

org.apache.xmlgraphics:batik-bridge

dicaeffe avatar Dec 11 '20 10:12 dicaeffe

note: Bootstrap is recommended to be updated to 3.4.1

dicaeffe avatar Dec 11 '20 10:12 dicaeffe

Hi. What about https://nvd.nist.gov/vuln/detail/CVE-2020-11987 ? Fix: batik 1.14

mariusssi avatar Jan 12 '22 11:01 mariusssi

CVE-2022-21724 in postgresql, not fixed in 9.4.0.0-79

mariusssi avatar Jul 18 '22 05:07 mariusssi