Desktop Central is not vulnerable to CVE 2020-11984

Is Desktop Central vulnerable to this CVE?

No, Desktop Central is not vulnerable to CVE-2020-11984  vulnerability. Read the document fully for further details.

What was the issue?

In CVE-2020-11984, Apache suffered from bufferoverlfow vulnerability that may cause RCE. The vulnerable module was mod_proxy_uwsfgi. This affects Apache HTTP Server versions 2.4.33, 2.4.34, 2.4.35, 2.4.37, 2.4.38 and 2.4.39.

Why Desktop Central is not vulnerable to this CVE?

CVE-2020-11984 will not affect Desktop Central. The mod_proxy_uwsgi module enables uwsgi protocol's functionalities. We do not use the mod_proxy_uwsgi module and the uwsgi protocol's functionalitites.

Future plan for Upgrade

Although the Desktop Central is not vulnerable to this CVE, we'll be upgrading to the latest Apache HTTP Server version during our regular third-party components upgrade cycle.