Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
During our regular scans we found some vulnerabilities on libcurl.dll (cve mentioned below), we are using the qliksense version - 14.78.23 (August 2022 patch 16).
The recommendation is to upgrade to libcurl 8.4.0. Please suggest if there are any patches available for upgrading libcurl.
CVE-2023-38545 (Heap Buffer Overflow)
CVE-2023-38546 (Cookie Injection)
@Sangeeta This is not officially found by Qlik what I see, https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enter...
If you feel anything, please reach to your success engineer from Qlik.
Same here: CVE-2023-38545, Qlik Sense Enterprise on Windows February 2024 14.173.3
Scan found affected libcurl.dll versions in
C:\Program Files\Common Files\Qlik\Custom Data\QvOdbcConnectorPackage\...
Search of Qlik Community did not produce any references to CVE-2023-38545.
What would be a solution here?