Security Alert: Update your Self-Hosted 3CX Deployment

Pierre_3CX

Staff member
3CX Support
Joined
Aug 1, 2013
Messages
781
Reaction score
401

Action required due to a web server configuration vulnerability.​

3CX has released a security hotfix relating to a third party component. If your 3CX deployment is reachable from the public internet, apply the latest update immediately. 3CX hosted instances have already received the update.

Who is Affected

D...
Continue reading the Original Blog Post.
 
Last edited by a moderator:
You note that protected by a firewall can be patched during the maint window. Can you explain further on this? If the only open ports through the firewall are https and tunnel, does this need an out of band patch?
 
Thanks for the update @Pierre_3CX. Is the security risk in the 3CX software or underlying OS?
 
  • Like
Reactions: fxbastler
This is not related to the 3CX software itself but to a third-party component used by the system. More details will follow in a dedicated blog post early next week.
 
On-prem update applied very quickly during business hours, on a Friday no less :)
I'm not touching anything else for the rest of the day.
 
  • Like
Reactions: N_G
Thanks @MichaelB_3CX just wanted to make sure. Our tool does an api push to do the Update which doesn't trigger OS updates underlying so I wanted to verify we could use the API push. Thanks!
 
If you allow logins for web clients but you do not allow admin console access outside of your local internal network, are you safe and can wait until a maintenance window? We do have a firewall but we only allow necessary traffic and ports open for 3cx communications. @Pierre_3CX
 
Last edited:
  • Like
Reactions: kelpdesk and NCIA
Thanks for the fix and for making it available so quickly.

Is a apt update && apt -y dist-upgrade and reboot required (because some linux packages and the kernel are even waiting for updates)?
 
Last edited:
This is not related to the 3CX software itself but to a third-party component used by the system. More details will follow in a dedicated blog post early next week.
thanks.
 
Is there any additional information available on this? Or hardening our deployment before next week since this release came late in the day, and I am not able to update my production environment. Thank you,
 
Pierre - the automatic update / download is not working.

I am able to get Windows updates.... without any problems.
 
Pierre - I finally got it to work.

Had to restart everything twice and got it to work.

Thanks,
 
Thanks for the fix and for making it available so quickly.

Is a apt update && apt -y dist-upgrade and reboot required (because some linux packages and the kernel are even waiting for updates)?
No need, just the 3CX update is recommended to do ASAP as per blog post
 
No need, just the 3CX update is recommended to do ASAP as per blog post
Thanks for the clarification.
That made for a long night here in CEST yesterday. However, as a Silver Partner, we don't have many systems, and the process can also be automated (i.e. using PowerShell). All systems are now up to date.
 
Would you please include the realip nginx module? This is essential for deployments behind a reverse proxy.
 
This update is being flagged as Beta in our installs and not being applied as an automatic update either:

"Warning: this is an Alpha/Beta update. Some functionality might not be fully tested and may contain bugs. Alpha/Beta updates are not to be used in production environments and can not be reverted. Alpha/Beta updates enable you to update to the next beta or to the final Release."

Is this expected behaviour, and if so should the update be installed regardless?
 
If you allow logins for web clients but you do not allow admin console access outside of your local internal network, are you safe and can wait until a maintenance window? We do have a firewall but we only allow necessary traffic and ports open for 3cx communications. @Pierre_3CX

MY question is same as yours. I applied the update. It's already done.
We're self-hosted with an on prem VM. Of course we do have a firewall but we have to open the Internet port -- that is 5001.

We don't need any users to access their extension Web interface remotely, but Presence info in the mobile app -- meaning the Team, Contacts, Recent, and Voicemail tabs -- are empty if 5001 isn't opened.

With 5001 opened for Mobile, the user's Web interface for each extension is available on the Web.

Admin extension is restricted to the LAN.

I'm very curious now (just to know) if my situation encompassed THE problem or if I would have been safe to skip the hotfix.
 
update is being flagged as Beta in our installs
All our clients on u8 auto installed, the other day. Are you sure you don’t have a prerelease of u9 installed?
 
This update is being flagged as Beta in our installs and not being applied as an automatic update either:

"Warning: this is an Alpha/Beta update. Some functionality might not be fully tested and may contain bugs. Alpha/Beta updates are not to be used in production environments and can not be reverted. Alpha/Beta updates enable you to update to the next beta or to the final Release."

Is this expected behaviour, and if so should the update be installed regardless?

Please check your Dashboard to confirm which version you are currently running.

If you are on 20.0.8.1131 (Release) or 20.0.9.987 (Beta), your system is already protected.

For production environments, the recommended version is 20.0.8.1131. If you are currently on 20.0.8.1121, you should see 20.0.8.1131 available as an update. This is a stable release and will be installed automatically, considering you have auto updates enabled.

If you are already running a 20.0.9.x alpha/beta builds on a testing system, you should update to 20.0.9.987 RC4 to ensure you are protected. Please note that 20.0.9.987 RC4 remains a beta release and will not be installed automatically.

If you are already on 20.0.8.1131, you may see 20.0.9.987 RC4 offered as an available update. However, if this is a production system, you should remain on 20.0.8.1131.

In short:
  • Production systems > Update to 20.0.8.1131
  • Testing systems already on 20.0.9.x > Update to 20.0.9.987 RC4
 
MY question is same as yours. I applied the update. It's already done.
We're self-hosted with an on prem VM. Of course we do have a firewall but we have to open the Internet port -- that is 5001.

We don't need any users to access their extension Web interface remotely, but Presence info in the mobile app -- meaning the Team, Contacts, Recent, and Voicemail tabs -- are empty if 5001 isn't opened.

With 5001 opened for Mobile, the user's Web interface for each extension is available on the Web.

Admin extension is restricted to the LAN.

I'm very curious now (just to know) if my situation encompassed THE problem or if I would have been safe to skip the hotfix.
If you allow logins for web clients but you do not allow admin console access outside of your local internal network, are you safe and can wait until a maintenance window? We do have a firewall but we only allow necessary traffic and ports open for 3cx communications. @Pierre_3CX


Hi @kelpdesk @GeekSqueak
I'm afraid not. Admin Console access is not relevant in this case. If your 3CX web service is exposed to the Internet, the recommended action is to apply the update.
 

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK