Security fixes

This topic lists the security fixes in Tanzu Application Platform v1.12 releases.

In this topic:

v1.12.1 Security fixes

This release has the following security fixes, listed by component and area.

Package Name Vulnerabilities Resolved
api-portal.tanzu.vmware.com
Expand to see the list
buildservice.tanzu.vmware.com
Expand to see the list
external-secrets.apps.tanzu.vmware.com
Expand to see the list
ootb-templates.tanzu.vmware.com
Expand to see the list

v1.12.0 Security fixes

This release has the following security fixes, listed by package.

Package Name Vulnerabilities Resolved
cert-manager.tanzu.vmware.com
Expand to see the list
cnrs.tanzu.vmware.com
Expand to see the list
fluxcd-source-controller.tanzu.vmware.com
Expand to see the list
ootb-templates.tanzu.vmware.com
Expand to see the list
sonarqube.component.apps.tanzu.vmware.com
Expand to see the list
sso.apps.tanzu.vmware.com
Expand to see the list
tap-gui.tanzu.vmware.com
Expand to see the list

About Linux Kernel CVEs

Kernel level vulnerabilities are regularly identified and patched by Canonical. Tanzu Application Platform releases with available images, which might contain known vulnerabilities. When Canonical makes patched images available, Tanzu Application Platform incorporates these fixed images into future releases.

The kernel runs on your container host VM, not the Tanzu Application Platform container image. Even with a patched Tanzu Application Platform image, the vulnerability is not mitigated until you deploy your containers on a host with a patched OS. An unpatched host OS might be exploitable if the base image is deployed.

check-circle-line exclamation-circle-line close-line
Scroll to top icon