You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to dspac...@googlegroups.com
Our central IT has warned us of an OpenSSL vulnerability and requested that we check with the developers/vendors for any needed patches. We are on DSpace 5.11. Does this version, or version 7.4 (which we are planning to move to) require a patch for this vulnerability?
Thank you!
Sarah
DSpace Technical Support
unread,
Oct 30, 2022, 2:38:01 PM10/30/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to DSpace Technical Support
Hi Sarah,
DSpace doesn't include any direct dependency to a specific version of OpenSSL, so there is nothing to patch for the application software itself.
You might need to patch your server that is hosting Tomcat (and/or Apache HTTPD if offloading SSL in a reverse proxy) for DSpace, however. See https://www.snbforums.com/threads/sans-critical-openssl-3-0-x-vulnerability.81516/ for some expected versions on various operating systems / distros, and how to check which version of OpenSSL is installed.