Uploaded image for project: 'JOC - JS7 Operations Center'
  1. JOC - JS7 Operations Center
  2. JOC-2226

Upgrade PostgreSQL Driver to version 42.7.11 due to 3rd party vulnerability CVE-2026-42198

    XMLWordPrintable

Details

    • Fix
    • Status: Released (View Workflow)
    • Minor
    • Resolution: Fixed
    • 2.5.13, 2.7.8, 2.8.3
    • 2.5.14, 2.9.0, 2.7.9, 2.8.4
    • None
    • None
    • CVE-2026-42198

    Description

      Current Situation

      Currently JS7 JOC Cockpit ships with PostgreSQL JDBC Driver 42.7.7. This version is flagged with vulnerability CVE-2026-42198.

      • We rate the impact of this vulnerability as medium because SCRAM is a valid authentication method that can be configured on a PostgreSQL Server. It has no direct impact on the JS7 JOC Cockpit,
      • Nevertheless, this is a security flaw of the PostgreSQL JDBC Driver that can be resolved by updating the JDBC Driver to version 42.7.11 which fixes the issue.
      • Customers should update the JDBC Driver as the issue can be exploited in any system that makes use of the vulnerable JDBC Driver version and not only when used with JS7 products.

      Desired Behavior

      Upgrade the PostgreSQL JDBC Driver to version 42.7.11 that resolves the issue.

      Risk Mitigation

      • Customers using JS7 JOC Cockpit 2.5.x, 2.7.x or 2.8.x can download the JDBC Driver from the DBMS vendor's download page and can update the JDBC Driver in their JOC Cockpit instance.
      • JOC Cockpit stores JDBC Drivers in theĀ <jetty-base>/lib/ext/joc directory. Users can shutdown JOC Cockpit, replace the vulnerable postgresql-42.7.7.jar file by postgresql-42.7.11.jar and start JOC Cockpit.

      Attachments

        Activity

          People

            sp Santiago Aucejo Petzoldt
            sp Santiago Aucejo Petzoldt
            Karuna Pawar Karuna Pawar
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: