Product Release Advisory - Elastic Application Runtime for VMware Tanzu Platform 10.2.4+LTS-T

Tanzu Kubernetes Runtime

7 more products

36319

05 November 2025

05 November 2025

CLOSED

CRITICAL

10

N/A

See CVE list in advisory

Product Release Advisory - Elastic Application Runtime for VMware Tanzu Platform 10.2.4+LTS-T

 

Advisory ID

TNZ-2025-0149

Tanzu Issue Date

2025-10-29

Updated on

 

 

 

Highest Score CVE from list below advisory details

Severity

Critical

CVSS V4 Vector

Unavailable

CVSS V4 Score

Unavailable (Sev: Unavailable)

CVSS V3.1 Vector

Unavailable

CVSS V3.1 Score

Unavailable (Sev: Unavailable)

CVSS V2 Vector

Unavailable

CVSS V2 Score

Unavailable (Sev: Unavailable)

 

  • Note: if cvss scores are "Unavailable" is is most likely due to the vulnerability being GHSA or BDSA without a matching CVE for nvd lookup.

 

Product Version Release Advisory

 

 

Security Fixes This release has the following security fixes, listed by component.

 

Component

Vulnerabilities Resolved

backup-and-restore-sdk

binary-offline-buildpack

capi

cf-autoscaling

cf-cli

cf-networking

cflinuxfs4

credhub

diego

dotnet-core-offline-buildpack

garden-runc

go-offline-buildpack

java-offline-buildpack

log-cache

loggregator

loggregator-agent

metric-registrar

mysql-monitoring

nats-monitor

nfs-volume

nginx-offline-buildpack

notifications-ui

push-apps-manager-release

push-usage-service-release

pxc

python-offline-buildpack

r-offline-buildpack

routing

ruby-offline-buildpack

silk

smb-volume

staticfile-offline-buildpack

statsd-injector

syslog

system-metrics-scraper

tuaa