<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco vulnerability - how to fix the problem ? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280379#M233509</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello Alex and thanks for your answers regarding these issues.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have to setup an alfresco server directly on a webserver, it will not be part of an intranet. In that case it seems to me the proxy vulnerability does not concern me, since there would not be any other servers or services to discover behind the alfesco server, is is exact ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance for your answer.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Yannick&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Jan 2016 10:20:50 GMT</pubDate>
    <dc:creator>yannickb</dc:creator>
    <dc:date>2016-01-22T10:20:50Z</dc:date>
    <item>
      <title>Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280370#M233500</link>
      <description>Hi,I'm currently using Alfresco CE 4.2.f, and I saw there is avulnerability on this version :http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9300http://seclists.org/bugtraq/2014/Jul/72My data are sensitive, and I want to prevent a disclosure, do you have an idea to fix or avoid this probl</description>
      <pubDate>Fri, 15 Jan 2016 09:09:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280370#M233500</guid>
      <dc:creator>benjamindupont</dc:creator>
      <dc:date>2016-01-15T09:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280371#M233501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;there is no official support for any Alfresco Community Edition release. There also won't usually be any security releases for a Community Edition release if a newer version is already available, and even without a newer version it is solely at the discretion of Alfresco. If moving to Alfresco 5.0 is not an option, then you can either try to merge any related fixes from 5.0 to your 4.2.f yourself, contact a 3rd party service provider that provides fixes / patches for Community Edition (i.e. Loftux) or switch to a paid Alfresco Enterprise subscription (Alfresco has provided hot-fix versions for such security vulnerabilities).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The proxy servlet can technically be disabled, but if you were to do this, than the entire Share web application will no longer work, so this is not an option from a "usability" point of view.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jan 2016 09:41:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280371#M233501</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-18T09:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280372#M233502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your reply Axel about the solutions. And for my information, could you explain how is it possible to disable the proxy servlet ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Ben&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 08:18:50 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280372#M233502</guid>
      <dc:creator>benjamindupont</dc:creator>
      <dc:date>2016-01-19T08:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280373#M233503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;By the way, to avoid the CMIS vulnerability (SSRF Proof of concept 2), do you know if there is a way to disable the CMIS access ? I can't find anything on this subject…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 09:59:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280373#M233503</guid>
      <dc:creator>benjamindupont</dc:creator>
      <dc:date>2016-01-19T09:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280374#M233504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;to disable the proxy controller you'd need to create a custom-slingshot-application-context.xml in /web-e extension/ directory and in that file override the webframeworkHandlerMappings bean to not include a mapping for /proxy/** (see this &amp;lt;a href="&lt;/SPAN&gt;&lt;A href="https://github.com/Alfresco/share/blob/bd807c91971c9ccdb196dbe09171c231d286fb29/share/src/main/resources/alfresco/slingshot-application-context.xml#L78" rel="nofollow noopener noreferrer"&gt;https://github.com/Alfresco/share/blob/bd807c91971c9ccdb196dbe09171c231d286fb29/share/src/main/resources/alfresco/slingshot-application-context.xml#L78&lt;/A&gt;&lt;SPAN&gt;"&amp;gt;default config&amp;lt;/a&amp;gt; for reference). Again, I advise against it since Share will stop working correctly / at all if you do disable it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 09:59:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280374#M233504</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-19T09:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280375#M233505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks again for your quick response and advises Axel.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a last question, to avoid the CMIS vulnerability (SSRF Proof of concept 2), do you know if there is a way to disable the CMIS access ? I can't find anything on this subject…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 10:05:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280375#M233505</guid>
      <dc:creator>benjamindupont</dc:creator>
      <dc:date>2016-01-19T10:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280376#M233506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;For the CMIS vulnerability you'd need to provide a modified web.xml in the /webapps/alfresco/WEB-INF directory which comments out / removes the /cmisbrowser servlet mapping. Note that there may be multiple mappings - one with CMISFileShareServlet and one called cmisbrowser. As far as I understand, the CMISFileShareServlet is the one affected by the advisory, not the cmisbrowser one. If you disable cmisbrowser you close up the only interface to use CMIS 1.1 with Alfresco 4.2&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I don't know why CMISFileShareServlet was ever included - I could not see a valid use case for it in production systems.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 10:08:25 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280376#M233506</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-19T10:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280377#M233507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I directly modify the /tomcat/webapps/alfresco/WEB-INF/web.xml by comments out the servlet and servlet mapping for cmisbrowser or CMISFileShareServlet and both of them. After rebooting Alfresco, it seems there isn't any change (I currently test with a CMIS sync tool)… &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Did I miss something ?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 10:56:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280377#M233507</guid>
      <dc:creator>benjamindupont</dc:creator>
      <dc:date>2016-01-19T10:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280378#M233508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;It depends on which CMIS protocol variant the CMIS sync tool is using. For normal Alfresco and Share there shouldn't be any noticable change, only for CMIS clients that used the CMIS browser binding. If CMIS sync tool is capable of falling back to AtomPub or even SOAP, then the change would be transparent…&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jan 2016 16:36:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280378#M233508</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-19T16:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280379#M233509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello Alex and thanks for your answers regarding these issues.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have to setup an alfresco server directly on a webserver, it will not be part of an intranet. In that case it seems to me the proxy vulnerability does not concern me, since there would not be any other servers or services to discover behind the alfesco server, is is exact ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks in advance for your answer.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Yannick&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2016 10:20:50 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280379#M233509</guid>
      <dc:creator>yannickb</dc:creator>
      <dc:date>2016-01-22T10:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280380#M233510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Axel,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your precisions about CMIS! Could you just tell us (If you know of course!), if this threat concern only a server which is placed with others servers (intranet) or not ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2016 14:03:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280380#M233510</guid>
      <dc:creator>benjamindupont</dc:creator>
      <dc:date>2016-01-28T14:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco vulnerability - how to fix the problem ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280381#M233511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The threat concerns any server in a networked environment. Only if the Alfresco server in question would be prevented from making any outbound HTTP(S) connection attempts would you avoid the "network / port scan" part of the vulnerability. And technically you can't restrict the file-level access to a level where you aren't still affected by the "file scan" part of the vulnerability.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jan 2016 16:58:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-vulnerability-how-to-fix-the-problem/m-p/280381#M233511</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2016-01-28T16:58:16Z</dc:date>
    </item>
  </channel>
</rss>

