Consensys / tessera

Tessera - Enterprise Implementation of Quorum's transaction manager
https://docs.tessera.consensys.net/
Apache License 2.0
177 stars 108 forks source link

tessera 22.10.0 is having vulnerabilities for libexpat, login and passwd libraries #1507

Open rupesh-pithva opened 1 year ago

rupesh-pithva commented 1 year ago

we are getting below vulnerabilities for latest tessera 22.10.0 image. Please let us know when the new image will be available with the fixes for this vulnerabilities.

image

sushilsaha1111 commented 1 year ago

@antonydenyer Please see the details above. The latest Tessera image is showing some vulnerabilities

rupesh-pithva commented 1 year ago

@antonydenyer there is another vulnerability raised for tessera image.

Please could you let us know when the new drop of the tessera image will be available with the fixes. Details below:- vulnerability name: - Java (Maven) Security Update for org.yaml:snakeyaml (GHSA-w37g-rhq8-7m4j)

Refer to Github security advisory GHSA-w37g-rhq8-7m4j for updates and patch information. Patch: Following are links for downloading patches to fix the vulnerabilities:

GHSA-w37g-rhq8-7m4j:org.yaml:snakeyaml