High-security-issue-affecting-Mule-runtimes-of-all-supported-versions-March-19th-2020

52 views Asked by At

Mule has recommended a security update on 19th March which was supposed to be for all supported version of Mule. The below URL is dead:

https://help.mulesoft.com/s/article/High-security-issue-affecting-Mule-runtimes-of-all-supported-versions-March-19th-2020

Could someone help what this vulnerability or security patch was about?

I am using Mule runtime v3.9.0

As per the latest article, I could only find out that the security patch on 19th March has some issues and was fixed by mule through https://help.mulesoft.com/s/article/Error-Provided-value-xx-is-not-compliant-with-the-format-datetime-provided-in-rfc3339

1

There are 1 answers

3
aled On

The URL is valid but it requires to be logged in from a customer account to access it. If you are a customer you have to be logged in Help Center before accessing the URL.

If you are not a customer I would assume that you are using Mule Community Edition 3.9.0. I'm not sure if the community edition is affected by the issue or not. You should download the latest hotfix release, 3.9.0-hf2, just in case.

The security patch introduced more strict date time validation, which could cause issues for applications that previously accepted invalid date time values, as explained in the second KB article you shared.