False Alarm due to Security Team scanning ConnectALL Backup location for CVE-2023-46604
search cancel

False Alarm due to Security Team scanning ConnectALL Backup location for CVE-2023-46604

book

Article ID: 397495

calendar_today

Updated On:

Products

ConnectAll On-Prem ConnectALL

Issue/Introduction

ConnectALL requires taking backup during the upgrade and backup can stay on the server as long as it is deleted manually.

Customer in 3.7 version reported CVE-2023-46604 as security tool scanned backup location.

Environment

3.7.x

Resolution

Please make sure the vulnerability reported is for ConnectALL base location not backup. If it is for backup location, delete the backups and run the scan again.

If it is true vulnerability, verify the ActiveMQ jar versions under ../ConnectALL/Broker/apache-artemis-##/lib and contact Support Team for assistance.