Ask Questions and Find Answers
Important:
Ask is now read-only. You can review any existing questions and answers, but not add anything new.
But - don't panic! While ask is no more, we've replaced it with discuss - the new Liferay Discussion Forum! Read more here here or just visit the site here:
discuss.liferay.com
RE: Sonatype High Hibernate CVE-2020-25638 in Liferay7.4 GA19
Hello, we did a sonatype scan against liferay 7.4.3.19 GA19 and found that there is hibrenate component com.liferay:org.hibernate.core:3.6.10.LIFERAY-PATCHED-6 that is vulnerable. Its also shown in maven as vulnerable component, https://mvnrepository.com/artifact/org.hibernate/hibernate-core/3.6.10.Final. Is liferay will be sending a GA release to upgrade to a non-vulernable hibernate component? For example using hibernate core 6.0.0 whioch s not vulenrable.
Thanks,
Kevin
You can disclose security issues at issues.liferay.com and use either the private or secure drop down to keep bots away.
sure will try that approach. Thanks
Created jira ticket. Do you know if will get a response from liferay?
Created the ticket. How soon will get an answer
Powered by Liferay™