Spring Framework Vulnerabilities (CVE-2022-22965, CVE-2022-22963, CVE-2022-22947)

April 5, 2022 | KB: 1014369
Laserfiche Cloud, Laserfiche 11, Laserfiche 10

Summary

Laserfiche is aware of the recently publicly disclosed vulnerabilities affecting the Spring Framework for Java as described in:

Laserfiche Cloud and Laserfiche's downloadable software products are not affected by these vulnerabilities in the Spring Framework for Java.

Other Mitigations

Customers using the Java Repository Access (JRA) library distributed with the Laserfiche Software Development Kit (SDK) are responsible for any use of the Spring Framework in their own custom projects. JRA itself is not directly affected by the above vulnerabilities.

Related Links