<?xml-stylesheet type="text/xsl" href="https://sugarclub.sugarai.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>January 5, 2023: Security vulnerability update and FAQ</title><link>/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><description>Please see January 13, 2023: Security Vulnerability Update for the most recent updates, including information about the final report from our third-party forensics firm. 
 
 SugarCRM recently became aware of a publicly disclosed vulnerability affecting</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: January 5, 2023: Security vulnerability update and FAQ</title><link>https://sugarclub.sugarai.com/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><pubDate>Mon, 16 Jan 2023 13:23:50 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:511e446f-fa64-47e6-b825-90122fdc6307</guid><dc:creator>Logamurugan Pilavadi</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;&lt;span&gt;Why is there a difference between patch to be applied on .htaccess and&amp;nbsp;&lt;/span&gt;&lt;span&gt;install_utils.php? Patch required for&amp;nbsp;install_utils.php missing / and&amp;nbsp;&lt;/span&gt;&lt;span&gt;log4php in the pattern&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3112&amp;AppID=12&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: January 5, 2023: Security vulnerability update and FAQ</title><link>https://sugarclub.sugarai.com/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><pubDate>Fri, 13 Jan 2023 20:32:27 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:511e446f-fa64-47e6-b825-90122fdc6307</guid><dc:creator>Club Concierge</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;span&gt;This post has been updated to reflect the current status of SugarCRM&amp;rsquo;s actions and knowledge. Updates include updated instructions based on the&amp;nbsp;&lt;/span&gt;&lt;a href="/explore/product-updates/b/enterprise-professional-updates/posts/security-release-notification-12-0-2-and-11-0-5"&gt;release of the 12.0.2 and 11.0.5 patches&lt;/a&gt;&lt;span&gt;, information regarding the official CVE report, and additional instructions on how to locate possible evidence to help determine if you have been affected.&lt;/span&gt;&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3112&amp;AppID=12&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: January 5, 2023: Security vulnerability update and FAQ</title><link>https://sugarclub.sugarai.com/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><pubDate>Fri, 13 Jan 2023 14:52:38 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:511e446f-fa64-47e6-b825-90122fdc6307</guid><dc:creator>Junaid Usman</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;Thanks for the quick patch.&lt;/p&gt;
&lt;p&gt;It is very unfortunate that an official statement from the SugarCRM side came on the&amp;nbsp;4th of Jan while the vulnerability was announced on the 28th of December. Considering this is a 0-day Auth bypass, it would&amp;nbsp;have been better if the announcement was made as soon as it is public; so that customers can take some precautionary measures while waiting for a quick patch.&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3112&amp;AppID=12&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: January 5, 2023: Security vulnerability update and FAQ</title><link>https://sugarclub.sugarai.com/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><pubDate>Fri, 13 Jan 2023 01:52:36 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:511e446f-fa64-47e6-b825-90122fdc6307</guid><dc:creator>Francesca Shiekh</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;For those still on Professional, the upgrade to 11.0.5 brings back Bug&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;87739&lt;/span&gt;&lt;span&gt;&amp;nbsp;and shows up as a database mismatch for fields of type INT.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3112&amp;AppID=12&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: January 5, 2023: Security vulnerability update and FAQ</title><link>https://sugarclub.sugarai.com/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><pubDate>Tue, 10 Jan 2023 00:40:24 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:511e446f-fa64-47e6-b825-90122fdc6307</guid><dc:creator>Club Concierge</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;This post has been updated to reflect findings related to instances of Sugar where SugarIdentity is enabled. We have determined that the vulnerability could not impact instances that had SugarIdentity enabled. For help in determining if SugarIdentity was enabled on your instance, instructions can be found &lt;a href="https://support.sugarcrm.com/Documentation/SugarCloud_Services/SugarIdentity/SugarIdentity_Guide/#Determining_if_Your_Instance_Uses_SugarIdentity" rel="noopener noreferrer" target="_blank"&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3112&amp;AppID=12&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item><item><title>RE: January 5, 2023: Security vulnerability update and FAQ</title><link>https://sugarclub.sugarai.com/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update</link><pubDate>Fri, 06 Jan 2023 18:45:45 GMT</pubDate><guid isPermaLink="false">5c521d64-519d-47a6-9065-134618b211bf:511e446f-fa64-47e6-b825-90122fdc6307</guid><dc:creator>Club Concierge</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;Additional questions added:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update#mcetoc_1gm44cmhs3"&gt;Once patched, what should customers hosted outside of SugarCloud or Sugar managed hosting be on the lookout for?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="/engage/b/sugar-news/posts/jan-5-2023-security-vulnerability-update#mcetoc_1gm45iuhf9"&gt;What is the vulnerability that was identified?&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Please click the &amp;quot;&lt;strong&gt;Turn Comment notifications on&lt;/strong&gt;&amp;quot; button on this post to be notified of any updates&lt;/p&gt;&lt;img src="https://sugarclub.sugarai.com/aggbug?PostID=3112&amp;AppID=12&amp;AppType=Weblog&amp;ContentType=0" width="1" height="1"&gt;</description></item></channel></rss>