Details
-
Fix
-
Status: Released (View Workflow)
-
Minor
-
Resolution: Fixed
-
2.7.8, 2.8.4
-
None
-
None
-
CVE-2026-54291
Description
Current Situation
JS7 JOC Cockpit ships with the postgresql jdbc driver version 42.7.11 (2.8.4) and 42.7.7 (2.7.8) respectively.
These version are affected by a vulnerabiltity CVE-2026-54291.
We rate this vulnerability as Low because the attack scenario assumes that the attacker already has means to intercept the TLS connection at hand. Also the problem can easily be fixed as described below in the workaround section.
Desired Behavior
JS7 JOC Cockpit should use version 42.7.12 of the driver, that fixes the issue.
Workaround
Download the driver version 42.7.12 from the vendor site and replace the driver in use.