This is an old revision of the document!


Stages and OpenSSL 3.x Vulnerability CVE-2022-3358

The Stages managed services *.stages.digital and *.stagesasaservice.com are not impacted.

On premise Stages installations are not impacted, unless all of the following conditions apply:

OpenSSL 3.0.0 - 3.0.5 is installed on your operating system. You can check by executing “openssl version” on the command line.

​​​​​​​OpenSSL usage is explicitly enabled by removing the comments around

<!– <Listener className=“org.apache.catalina.core.AprLifecycleListener” SSLEngine=“on” /> –>

in …/conf/server.xml. The default configuration uses the Java SSL implementation, which is not vulnerable.