Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content
Announcements
WEBINAR June 25, 2025: Build on Apache Iceberg with Qlik Open Lakehouse - REGISTER TODAY
cancel
Showing results for 
Search instead for 
Did you mean: 
BernieMaf
Partner - Contributor II
Partner - Contributor II

Critical OpenSSL Vulnerability

Good day

When should we expect the release of QB-28631 or QB-28762, now we are sitting with a situation (https://cyberpress.org/openssl-vulnerability/) and Microsoft Defender has picked up Qlik Sense's OpenSSL files need to be updated.

 

Affected Files:

c:\program files\common files\qlik\custom data\qvodbcconnectorpackage\drill\lib\openssl64.dlla\libcrypto-3-x64.dll
c:\program files\common files\qlik\custom data\qvodbcconnectorpackage\drill\lib\openssl64.dlla\libssl-3-x64.dll


c:\programdata\package cache\af7aeebf-6f94-4a09-9113-21295ed47105\qvodbcconnectorpackage\oracle\lib\libcrypto-3-x64.dll
c:\programdata\package cache\af7aeebf-6f94-4a09-9113-21295ed47105\qvodbcconnectorpackage\oracle\lib\libssl-3-x64.dll
c:\programdata\package cache\af7aeebf-6f94-4a09-9113-21295ed47105\qvodbcconnectorpackage\spark\lib\libcurl64.dlla\openssl64.dlla\libcrypto-3-x64.dll

c:\programdata\package cache\af7aeebf-6f94-4a09-9113-21295ed47105\qvodbcconnectorpackage\spark\lib\libcurl64.dlla\openssl64.dlla\libssl-3-x64.dll
c:\programdata\package cache\af7aeebf-6f94-4a09-9113-21295ed47105\qvodbcconnectorpackage\spark\lib\openssl64.dlla\libcrypto-3-x64.dll
c:\programdata\package cache\af7aeebf-6f94-4a09-9113-21295ed47105\qvodbcconnectorpackage\spark\lib\openssl64.dlla\libssl-3-x64.dll

 

cc: @Lass 

 

Labels (3)
7 Replies
BernieMaf
Partner - Contributor II
Partner - Contributor II
Author

@Nick_Asilo can you please assist?

tin_u
Partner - Contributor II
Partner - Contributor II

Do we have any status on this that Qlik recognize this as an issue?

BernieMaf
Partner - Contributor II
Partner - Contributor II
Author

Nothing at all.
QLIK support is non-existent on issues we raise. I guess they are willing to pay when we get breached because of their products.
Security is not that important to them, postmen are quicker than their security team when it comes to delivery.

tin_u
Partner - Contributor II
Partner - Contributor II

Just got a reply from support regarding my ticket where i raised some of these concerns, and it seems like these issues will be addressed in the May 2025 Initial Release..

BernieMaf
Partner - Contributor II
Partner - Contributor II
Author

I won't get my hopes up. We were told last year that it would be addressed in the November 2024 release, but here we are.

tin_u
Partner - Contributor II
Partner - Contributor II

Fair enough.. lets cross our fingers i guess..

BernieMaf
Partner - Contributor II
Partner - Contributor II
Author

I have already gone through the Technical Preview for May 2025 https://community.qlik.com/t5/Release-Notes/Qlik-Sense-Enterprise-on-Windows-Technical-Preview-for-M... and I don't see the resolution for our issue.
The only thing close to our issue is the QB-29866 (Qlik Sense: libcurl library updates).