Affected Product: Nuxeo Enhanced Viewer
Affected Product Versions: All versions
A vulnerability has been reported in Nuxeo Enhanced Viewer where a possible server-side request forgery (SSRF) issue could occur. The Hyland Security team has deployed a mitigation in our cloud instance.
We strongly advise self-managed customers to likewise apply the following configuration change to mitigate the risk of this vulnerability:
Fixed Versions: 2.1.4 and higher
Upgrading to this version can be applied in lieu of performing the mitigation steps above.
If you have questions or require additional assistance, please open a support ticket with us.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.