IMPORTANT NOTE FROM 2020-05-12 Tomcat had a bug with AJP and IIS over HTTPS. Ivy 7.0.17 and 8.0.4/8.0.5 are affected by this bug. You will need to upgrade to 7.0.18 and 8.0.6. The Axon.ivy Digital Business Platform is using Tomcat as web server. Ghostcat 👻😼 (CVE-2020-1938) is a security vulnerability in Tomcat and is related to the AJP protocol. AJP is a binary protocol and is used in conjunction with a reverse proxy like IIS or Apache httpd. A secure Axon.ivy Engine setup always includes a reverse proxy, like the following example:
HTTP or HTTPS is also possible as communication protocol between the reverse proxy and the Axon.ivy Engine, but AJP is the most used setup, especially in Windows environments. Are you affected by this vulnerability?
How to fix this without updating? Is your reverse proxy running on the same host as the Axon.ivy Engine?
What will change in Axon.ivy 7.0.17 and 8.0.6? Axon.ivy will come with the latest Tomcat version:
Tomcat has changed the default behavior of the AJP port. AJP is now bound by default to localhost and not anymore to every network interface (nic). This means nobody can access the Axon.ivy Engine from another host via AJP. Furthermore the AJP port is now also disabled by default in Axon.ivy 7.0.18. What do you have to do when upgrading to 7.0.18? Is your reverse proxy running on the same host as the Axon.ivy Engine?
If you don't use a reverse proxy at all, then you need to disable the AJP port by setting the system property What do you have to do when upgrading to 8.0.6? Is your reverse proxy running on the same host as the Axon.ivy Engine?
isapi.dll and mod_jk.so upgrades We also bundle with the upcoming release the latest version of What about You may have read something about secret or secretRequired. This is an alternative way to protect the communication between the reverse proxy and Axon.ivy Engine. We believe that a secure communication between the reverse proxy and the Axon.ivy Engine should be protected by firewall rules even in trusted networks and therefore this is not needed. If you don't have the same opinion, we would love to hear 👂 why! If you really want to use Security is important to us 💯 % We, the platform development team, take security very seriously. If you have any questions or find other weaknesses, please do not hesitate to contact us. asked 17.03.2020 at 10:00 Alex Suter ♦♦ |
Thanks for sharing the details on this crucial change @Alex Suter answered 14.05.2020 at 02:52 SupportIvyTeam ♦♦ |
Once you sign in you will be able to subscribe for any updates here
By RSS:Markdown Basics
Tags:
Asked: 17.03.2020 at 10:00
Seen: 1,901 times
Last updated: 14.05.2020 at 02:52