VMware has released critical security updates to address 47 vulnerabilities across multiple VMware Tanzu Greenplum products, including 29 issues in VMware Tanzu Greenplum Backup and Restore and 18 bugs in various components of VMware Tanzu Greenplum. 

The security advisories, published on April 7, 2025, include patches for vulnerabilities with CVSS scores as high as 9.8, indicating critical severity levels that require immediate attention from organizations using these products.

Significant Security Vulnerabilities Addressed

Among the 29 vulnerabilities in VMware Tanzu Greenplum Backup and Restore, several are classified as critical, including CVE-2023-39320, CVE-2024-24790, and GHSA-v778-237x-gjrc. 

CVE-2023-39320 and CVE-2024-24790 are critical vulnerabilities (CVSS 9.8) likely involving privilege escalation or remote code execution risks in backup operations. 

GHSA-v778-237x-gjrc addresses a critical authorization bypass in Golang’s golang.org/x/crypto module (versions