-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 7.0 DE (7.0.10), 7.1 DXP (7.1.10), 7.2 DXP (7.2.10)
-
CVSS Base Score:9.8
-
CVSS Vector String:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
-
7.1 Fix Pack Version:18
-
7.2 Fix Pack Version:6
The Liferay Connector to Elasticsearch 6 and Liferay Connector to Elasticsearch 7 modules (v3.0.0 and v3.0.1) in Liferay DXP 7.0, 7.1 and 7.2 is bundled with Netty 4.1.43, which has known vulnerabilities. Fore more details, please see CVE-2019-20444, CVE-2019-20445, CVE-2020-7238, CVE-2020-11612
Fix Availability
- DXP 7.2:
- Connector to Elasticsearch 6: Bundled, fixed in FP6+.
- Connector to Elasticsearch 7: Marketplace, v3.1.0+. Subscribers can request the fix through Support as a Hotfix LPKG.
- DXP 7.1:
- Connector to Elasticsearch 6: Bundled, fixed in FP18+.
- DXP 7.0:
- Connector to Elasticsearch 6: Marketplace, will be included in a future release. Subscribers can request the fix through Support as a Hotfix LPKG.