04-04-2022 10:27 AM
Is Hyland able to provide any information on whether ACS, APS or any related product are impacted by the "Spring4Shell" Spring Framework RCE vulnerability?
Announcement from Spring : https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
Many thanks in advance for your feedback
Regards !
04-04-2022 10:34 AM
Hi, Mickael.
We're still evaluating detailed impact of this vulnerability.
Attacked libraries and versions are used in some of our products, however this is not the only condition to met.
We sill provide an official communication later this week, but it looks like the impact will be very low or none at all.
Regards
10-11-2022 03:45 AM
@Atol Support Team:
The official Information can be found here:
and
https://community.hyland.com/connect/hyland-research-and-development/security-advisories/spring-fram...
Alfresco Process Services (APS) is impacted from "Spring4Shell"
--> Upgrade to at least APS version 2.3.1
Alfresco Content Services (ACS) is NOT impacted from "Spring4Shell" in its default configuration.
--> I fixed the security issue at the customer by upgrading the Tomcat version and can recommend to do so as well.
See: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
More information:
https://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.20_(market) ;
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.62_(remm) ;
https://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.78_(market)
/content-services/tomcat/bin$ ./version.sh | grep version
04-04-2022 10:34 AM
Hi, Mickael.
We're still evaluating detailed impact of this vulnerability.
Attacked libraries and versions are used in some of our products, however this is not the only condition to met.
We sill provide an official communication later this week, but it looks like the impact will be very low or none at all.
Regards
09-28-2022 04:35 AM
Hi Angel,
Do you have any recommendations/updates concerning this issue ?
Best regards,
Marie Magnier.
10-11-2022 03:45 AM
@Atol Support Team:
The official Information can be found here:
and
https://community.hyland.com/connect/hyland-research-and-development/security-advisories/spring-fram...
Alfresco Process Services (APS) is impacted from "Spring4Shell"
--> Upgrade to at least APS version 2.3.1
Alfresco Content Services (ACS) is NOT impacted from "Spring4Shell" in its default configuration.
--> I fixed the security issue at the customer by upgrading the Tomcat version and can recommend to do so as well.
See: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
More information:
https://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.20_(market) ;
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.62_(remm) ;
https://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.78_(market)
/content-services/tomcat/bin$ ./version.sh | grep version
Explore our Alfresco products with the links below. Use labels to filter content by product module.