OpenSSL Heartbleed

Discuss all problems you have with Servoy here. It might help to mention the Servoy version and Operating System version you are using

OpenSSL Heartbleed

Postby Jan Blok » Wed Apr 16, 2014 9:30 am

As you may know there is a vulnerability found in OpenSSL.
We received the question from several customers:
Do we have any exposure to the OpenSSL Heartbleed vulnerability with our Servoy deployments?

The answer is no.
Java and JVM are not using OpenSSL and therefor are not affected.
If you are are using postgress with ssl db connections, you might want to read this.
Jan Blok
Servoy
Jan Blok
 
Posts: 2684
Joined: Mon Jun 23, 2003 11:15 am
Location: Amsterdam

Re: OpenSSL Heartbleed

Postby Yeroc » Wed Apr 16, 2014 10:21 pm

I suppose this ought to be obvious but if you're using Apache or another web server in a reverse-proxy configuration in front of Servoy with that web server handling SSL termination then you could still be vulnerable...

Corey
Yeroc
 
Posts: 109
Joined: Tue Aug 12, 2008 1:12 am
Location: Calgary, AB, Canada


Return to Discuss possible Issues and Bugs

Who is online

Users browsing this forum: No registered users and 6 guests