Page 1 of 1

Security Vulnerabilities on 6.3 - CE

PostPosted:Fri Aug 27, 2021 6:12 am
by MohamadAli
Hello,

In our company we are looking to deploy an edms, and OpenKM is on the list of possible solutions.
For now we are exploring 6.3 - CE, we have been working with it for 3 months (80 employees), it is hosted on a local server (no internet access).

To connect it to internet, we were looking for security issues and found that there is a Vulnerability in 6.3 CE (https://www.cvedetails.com/vulnerabilit ... penkm.html).

My question is, is there a way to solve this vulnerability in CE or should we switch to professional edition?

Also, can you provide us some info about pricing for professional edition?

Thanks

Re: Security Vulnerabilities on 6.3 - CE

PostPosted:Fri Aug 27, 2021 6:52 pm
by jllort
These vulnerabilities have been corrected in the last OpenKM version and currently, the application should not be affected by them. Usually, when users detect a vulnerability contact us, give time to solve it, and then they report in this kind of page ( that is the regular process ).

Re: Security Vulnerabilities on 6.3 - CE

PostPosted:Mon Aug 30, 2021 10:11 am
by MohamadAli
Thanks for your answer,

In the last version, you mean CE 6.3? which is downloadable from https://www.openkm.com/en/download.html? or should I fetch it from github?

Re: Security Vulnerabilities on 6.3 - CE

PostPosted:Wed Sep 01, 2021 3:01 pm
by jllort
The OKMInstaller.jar available from here https://www.openkm.com/en/download.html will install the latest version of OpenKM ( last release from github ). You should use the installer ( in the download section of the website have a video where explain how to use the installer, watch it ).