Issue
- There have been security announcements that are deemed to be a high-risk vulnerability that is caused by curl 8.4.0.
Environment
- DXP 7.3
Resolution
- Liferay DXP does not use the libcurl library. In conclusion, Liferay DXP is not vulnerable to this type of curl security vulnerability.
- Liferay DXP Docker Images do however contain the affected curl libraries, included as a part of Ubuntu. Liferay DXP or scripts within the image do not call curl with any of the affected options or environment variables.
Additional Information
- You may read about if your version of Docker Images is affected here, CVE-2023-38545 curl: SOCKS5 heap buffer overflow. There have been newer released versions of Docker Images (d5.0.47 or newer) that have addressed this existing vulnerability.