11-21-2022 09:20 AM
Goog morning:
I'd like to know if the community versions of Alfresco have also this issue. If so, are there any patches ready to fix this problem?
Thank you.
Best regards,
11-21-2022 09:49 AM
May you give more details on the issue?
I'm not aware of any similar to the one you describe.
11-21-2022 10:39 AM
We received this email from Hyland last Friday:
But I'm unable to access the detail page for this. @angelborroy is there a CVE description with details about version & general impact of this vulnerability?
Thanks!
11-21-2022 11:05 AM
I'm not able to find that Technical Bulletin, not sure if that was published / distributed by error.
11-22-2022 09:00 AM
Hello, Angel:
thank you for your answer. Can you verify this point with the development team? If this security issue also happens on Community edition, a patch is needed (in orther to set the maximum memory an script can manage). There are several customers in the world that use Alfresco Community in production environment.....
Thank you.
Best regards.
11-22-2022 09:26 AM
Server side JavaScript code in Alfresco Repository is allowed, but this is mainly restricted to administrator users. The product can be limited / restricted in features in order to protect yourself from your administrators... but does this make sense?
Explore our Alfresco products with the links below. Use labels to filter content by product module.