Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Hello!
There are several outdated OpenSSL libs with vulnerabilities in connector package
QS May 2024 Patch 5
Nessus scan results:
[
"OpenSSL Project OpenSSL 1.1.1h (C:\\Program files\\Qlik\\Sense\\Repository\\Postgresql\\12.5\\Bin\\)",
"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Libcurl64.dlla\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Hive\\Lib\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.1k (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Impala\\Lib\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.1n (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Mysql\\Lib\\Openssl64.dlla\\)",
"OpenSSL Project OpenSSL 1.1.0j (C:\\Program files\\Common files\\Qlik\\Custom data\\Qvodbcconnectorpackage\\Phoenix\\Lib\\Openssl64.dlla\\)"
]
Where we can download updated drivers or libs?
Have this been addressed by anyone? Patch 11 still has this version on our instances, upgrading to Patch 15 came with the following:
I am also facing the same issue, have opened the ticket with Qlik support and here is the answer i have received.
It seems that Qlik Sense Enterprise has OpenSSL libraries at
C:\program files\common files\qlik\custom data\qvodbcconnectorpackage\...\lib
OpenSSL 3.0.15 has security fixes - https://openssl-library.org/news/openssl-3.0-notes/index.html
CVSS score : CVE-2024-6119, CVE-2024-5535
This is an already reported issue and there are plans to update the Open SSL libraries in future Qlik Sense releases but we don't have ETA on this. I know this is an inconvenience for you but please watch out for our release notes to identify if the libraries are updated by tracking directly on our Community Page, kindly subscribe to receive notifications on the latest release notes for patches and news releases.
https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes
https://community.qlik.com/t5/Management-Governance/Vulnerabilities-OpenSSL-1-1-0/td-p/2480937
You may need to plan on upgrading your Qlik Sense since it appears the patch will be in later versions of 2025.