Security Updates

Servoy announcements

Security Updates

Postby sean » Mon Feb 26, 2024 11:31 pm

Last week we released 2023.12.2 and LTS branches to provide a security update for a potential vulnerability in the NG Client (NG1 and Titanium).

Although it was already mentioned in the forum post and release notes, we wanted to make a separate communication to reiterate this is a security patch and that we strongly recommend our customers to update production systems to a supported version as soon as possible.

If you are on a recent version, then you should move to 2023.12.2.

If you are on LTS release or any older version please upgrade to 2022.3.7 LTS or 2023.3.5 LTS

These updates are available through the download site

Please let us know if you have any questions or issues updating.

Thanks,
The Servoy Product Team
sean
 
Posts: 370
Joined: Mon May 21, 2007 6:26 pm
Location: USA

Re: Security Updates

Postby robert.edelmann » Tue Feb 27, 2024 11:56 am

Just for clarification, since I can't find any deeper information, I assume the following:
- If the system is directly accessible from the internet it should best be patched yesterday
- if the system is only accessible internally or via vpn we should do this this week, but we don't have to pull an all-nighter to do this.
mit freundlichen Grüßen
Robert Stefan Edelmann
User avatar
robert.edelmann
 
Posts: 95
Joined: Wed Aug 14, 2013 6:12 pm

Re: Security Updates

Postby sean » Tue Feb 27, 2024 3:48 pm

Hi Robert, That is correct: An application which is firewalled is far less vulnerable
(Also this does not pertain to legacy clients: weblicent, smartclient)
Software Engineer
Servoy USA
sean
 
Posts: 370
Joined: Mon May 21, 2007 6:26 pm
Location: USA

Re: Security Updates

Postby steve1376656734 » Thu Feb 29, 2024 2:58 pm

Hi Sean,

Can you share what the security update was for as there is no information in the release notes?

Thanks
Steve
Steve
SAN Developer
There are 10 types of people in the world - those that understand binary and those that don't
steve1376656734
 
Posts: 330
Joined: Fri Aug 16, 2013 2:38 pm
Location: Ashford, UK

Re: Security Updates

Postby sean » Thu Feb 29, 2024 6:04 pm

Hi Steve,

The update is indeed mentioned in the release notes, however the lack of specifics is intentional. The vulnerability is NOT already a known CVE (it was discovered internally). Therefore, we don't want to provide any details that would assist hackers to potentially exploit it :-)

What I will say is that it affects recent versions of NG Clients (Titanium & NG1). Legacy clients (Smart/Web client) and headless clients are not at risk.

We (always) recommend to update to a supported version (LTS branch is fine) at your next convenience. If you want a more personal assessment, please send me a PM.

Best,
Sean
Software Engineer
Servoy USA
sean
 
Posts: 370
Joined: Mon May 21, 2007 6:26 pm
Location: USA


Return to Announcements

Who is online

Users browsing this forum: No registered users and 154 guests