It’s a special Thursday this week as we have a couple patches available today that also address the Node.js vulnerability. Please apply the appropriate patch as soon as possible.
If the initial version of Qlik Sense installed was prior to version June 2019 or earlier, then the Qlik Sense Root Certificate must be recreated. For more information on recreating certificates, please review the following materials:
As with all software, please follow best practices when upgrading by backing up your Qlik Sense environment and testing the patch in a QA environment first.
Be sure to subscribe to the Qlik Support Blog by clicking the green Subscribe button to stay up-to-date with the latest releases.
Recreating certificates is not as easy as deploying a patch, and could be error prone. So, what are the consequences/risks not recreating them ? Is there a real security risk, even for small companies with a single server and a few users ?
We created a Powershell script that will recreate the certificates that will hopefully make this process easier. Please see <article link> for recreating the certificates using Powershell. If the certificates are not recreated, Qlik will not take responsibility for any security breach within your environment. Please review the <node.js link> to review the risks.
I've read it already and didn't find anything which would require to regenerate Qlik's CA certificate. I have probably missed something, could you explain me ?
Node.js vulnerabilities fixed:
HTTP request smuggling using malformed Transfer-Encoding header (Critical) (CVE-2019-15605)
Not related
HTTP header values do not have trailing OWS trimmed (High) (CVE-2019-15606)
Not related
Remotely trigger an assertion on a TLS server with a malformed certificate string (High) (CVE-2019-15604)
Could be related (improper client certificate check) but that would crash TLS server (according to Qlik), quite annoying but not a security risk
@dvasseur That article is information from Node.js. The part that requires you to regenerate the certificates on the Qlik side is in the release notes for the patches. @rzenere_avvale is correct that it's due to upgrading the version of Node.js. There is also a FAQ regarding this that has some more information.
0
Likes
1,576 Views
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.