Skip to content

Commit

Permalink
Adding fixed events for thingsboard (#11294)
Browse files Browse the repository at this point in the history
* Adding Fixed Advisory GHSA-27hp-xhwr-wr2m for thingsboard

* Adding Fixed Advisory GHSA-5j33-cvvr-w245 for thingsboard

* Adding Fixed Advisory GHSA-mfj5-cf8g-g2fv for thingsboard

---------

Co-authored-by: octo-sts[bot] <[email protected]>
  • Loading branch information
octo-sts[bot] and octo-sts[bot] authored Jan 16, 2025
1 parent 8366bab commit 5e9f4dd
Showing 1 changed file with 12 additions and 0 deletions.
12 changes: 12 additions & 0 deletions thingsboard.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/tb-mqtt-transport/bin/tb-mqtt-transport.jar
scanner: grype
- timestamp: 2025-01-16T23:17:43Z
type: fixed
data:
fixed-version: 3.9-r1

- id: CGA-63mv-w982-8q6x
aliases:
Expand Down Expand Up @@ -149,6 +153,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/tb-mqtt-transport/bin/tb-mqtt-transport.jar
scanner: grype
- timestamp: 2025-01-16T23:17:42Z
type: fixed
data:
fixed-version: 3.9-r1

- id: CGA-6xwj-3x88-p9hm
aliases:
Expand Down Expand Up @@ -265,6 +273,10 @@ advisories:
type: pending-upstream-fix
data:
note: This CVE caused by async-http-client being brought in via Microsoft Azure SDK for Service Bus (version 3.6.7), which is used by ThingsBoard’s server-queue components, as a transitive dependency. This will require upstream maintainers to implement a remediation.
- timestamp: 2025-01-16T23:17:44Z
type: fixed
data:
fixed-version: 3.9-r1

- id: CGA-9cw3-8w4j-827w
aliases:
Expand Down

0 comments on commit 5e9f4dd

Please sign in to comment.