https://www.cve.org/CVERecord?id=CVE-2023-46604
Hi @gtiemens ,
Thank you for contacting Safe Software and for reporting this vulnerability.
Our team is currently investigating the vulnerability CVE-2023-46604 to determine if FME Form and Flow are affected.
I will update this thread as soon as I have further information.
Thank you for your patience.
Kezia
According to our assessment, we believe that the only component in FME Form and FME Flow possibly affected by this vulnerability is the JMSSender/Receiver (Form) & JMS Subscriber/Publisher (Flow). We do not expect your workspaces or automation workflows to be affected if you’re not using either of these transformers.
That being said, Apache ActiveMQ will be upgraded to a non-vulnerable version for the 2023.2 and 2024.0+ releases. We will also backport the fix to a 2023.1.2 release.