Tomcat's vulnerability CVE-2023-44487

Issue

  • Is DXP 7.4 affected by Tomcat's Rapid Reset CVE-2023-44487?

Environment

  • Liferay DXP 7.4

Resolution

  • If user is not using Tomcat with DXP, then it is not affected by “Tomcat's Rapid Reset CVE-2023-44487”.
  • If the user running Tomcat 9.0.81 or above, then you’re not affected by “Tomcat's Rapid Reset CVE-2023-44487”.
  • If user have not configured Tomcat to use HTTP/2, then you’re not affected by “Tomcat's Rapid Reset CVE-2023-44487”.
  • DXP is affected by CVE-2023-44487, it does include 3rd party libraries that are vulnerable to CVE-2023-44487.
  • Finally, “Tomcat's Rapid Reset CVE-2023-44487” is a vulnerability in Tomcat and not a vulnerability in DXP.

Additional Information

这篇文章有帮助吗?
0 人中有 0 人觉得有帮助