Ask Questions and Find Answers
Important:
Ask is now read-only. You can review any existing questions and answers, but not add anything new.
But - don't panic! While ask is no more, we've replaced it with discuss - the new Liferay Discussion Forum! Read more here here or just visit the site here:
discuss.liferay.com
RE: RE: Spring4Shell bug CVE-2022-22965 and Liferay 7.4
For Spring4Shell bug CVE-2022-22965 see link below. Is there plans for liferay to upgrade to Spring Framework 5.3.18 and 5.2.20. I know Spring team mention the work around is downgrading to java 8, upgrading tomcat and disallowing fields.
https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#am-i-impacted
Hi Kevin,
The fix for Spring4Shell is in Master as a part of: https://issues.liferay.com/browse/LPS-150754. It appears to be in the release branch for this Friday's release GA19.
Great, Thansk Jamie :)
Hi Jamie, I was able to install GA19 verify the Spring4Shell vulernabilty was gone and no need to upgrade since there is no schema changes and I am going from GA18 to A19. I know I extract the WAR and install in ROOT.war folder but how do I verify that I have GA19 installed once the portal application is running? Is there someting i can find in the ROOT.war or control panel?
Hi Kevin, you can find the build info in the Control Panel in Server Administration. The build info will appear at the top of the screen.
Great thanks Jamie.
Powered by Liferay™