Uploaded image for project: 'JOC - JS7 Operations Center'
  1. JOC - JS7 Operations Center
  2. JOC-2266

Upgrade PostgreSQL Driver to version 42.7.12 due to 3rd party vulnerability CVE-2026-54291

    XMLWordPrintable

Details

    • Fix
    • Status: Released (View Workflow)
    • Minor
    • Resolution: Fixed
    • 2.7.8, 2.8.4
    • 2.9.0, 2.7.9, 2.8.5
    • None
    • None
    • CVE-2026-54291

    Description

      Current Situation

      JS7 JOC Cockpit ships with the postgresql jdbc driver version 42.7.11 (2.8.4) and 42.7.7 (2.7.8) respectively.

      These version are affected by a vulnerabiltity CVE-2026-54291.

      We rate this vulnerability as Low because the attack scenario assumes that the attacker already has means to intercept the TLS connection at hand. Also the problem can easily be fixed as described below in the workaround section. 

      Desired Behavior

      JS7 JOC Cockpit should use version 42.7.12 of the driver, that fixes the issue.

      Workaround

      Download the driver version 42.7.12 from the vendor site and replace the driver in use.

      Attachments

        Activity

          People

            sp Santiago Aucejo Petzoldt
            sp Santiago Aucejo Petzoldt
            Gitesh Patidar Gitesh Patidar
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: