-
Notifications
You must be signed in to change notification settings - Fork 2
Description
It has come to our attention that the latest Windows version of TablePlus (6.8.1) includes vulnerable OpenSSL 3.0.15 DLLs
Default install paths:
c:\program files\tableplus\cmd\libcrypto-3-x64.dll
c:\program files\tableplus\libcrypto-3-x64.dll
c:\program files\tableplus\libssl-3-x64.dll
c:\program files\tableplus\x64\libcrypto-3-x64.dll
c:\program files\tableplus\x64\libssl-3-x64.dll
This version of OpenSSL is vulnerable to the following 3 CVEs:
- CVE-2024-13176
- CVE-2024-9143
- CVE-2025-9230
As OpenSSL 3.0.x goes end of life on the 7th September 2026, any OpenSSL 3.0.x use should be replaced with a supported version. Version 3.5 [LTS] is supported until 8th April 2030
Therefore please could you update the OpenSSL DLLs with either 3.0.18 (https://openssl-library.org/news/openssl-3.0-notes/) or 3.5.4 (https://openssl-library.org/news/openssl-3.5-notes/) to resolve these issues?