Foren

Heartbleed: What Liferay Customers and Community Need to Know

thumbnail
James Falkner, geändert vor 10 Jahren.

Heartbleed: What Liferay Customers and Community Need to Know

Liferay Legend Beiträge: 1399 Beitrittsdatum: 17.09.10 Neueste Beiträge
Earlier this week a new website vulnerability was disclosed to the public which affected many sites across the Internet, including liferay.com. This vulnerability, dubbed Heartbleed, was discovered in OpenSSL, a widely-used software library that implements SSL.

Our web team immediately updated the software that runs liferay.com to fix the vulnerability, and is now in the process of revoking and re-issuing our SSL certificates to ensure that the site is secure. Once this is complete, all users will be strongly advised to change their passwords used to access liferay.com. Another post will be made here once this has been done.

Liferay Portal and other Liferay products do not include OpenSSL and therefore are not directly affected, but if you are using Liferay software on your site along with software such as Apache or nginx, you should verify whether your site is affected, and follow steps listed here to update your website software and SSL certificates.

For more information on this issue and other security issues, read Liferay's security statement.
thumbnail
James Falkner, geändert vor 9 Jahren.

RE: Heartbleed: What Liferay Customers and Community Need to Know

Liferay Legend Beiträge: 1399 Beitrittsdatum: 17.09.10 Neueste Beiträge
Reminder: As of April 28, liferay.com servers have been patched and the SSL certificates have been refreshed, and all users are strongly advised to change their passwords. You can change your password by clicking on your profile picture at the upper right and navigating to Account -> My Account -> Password.