"Connection is closed", and Hazelcast vuln (Okapi, mod-erm-usage-harvester) Ladisch, Julian 14 Feb 2023 06:42 EST

Hi,

Okapi v4.14.9 has a bug that sometimes closes an HTTP connection before all data has been sent.
Okapi logs "The timeout period of 1ms has been exceeded".
https://issues.folio.org/browse/OKAPI-1155
Please upgrade to Okapi v4.14.10.
Okapi versions up to v4.14.8 are not affected.
Using the latest v4.14.x Okapi version is recommended for Morning Glory and Nolana.

Institutions that use Hazelcast should upgrade to fixed versions of Okapi and mod-erm-usage-harvester.
Their Hazelcast client has a bug in the connection caching allowing a remote unauthenticated
attacker to access and manipulate data in the cluster with the identity of another already
authenticated connection: https://nvd.nist.gov/vuln/detail/CVE-2022-36437
Affected versions:
mod-erm-usage-harvester v4.2.0 and all previous versions
Okapi v4.13.2 and all previous versions
Okapi v4.14.7 and all previous versions
Fixed versions:
mod-erm-usage-harvester v4.2.1 and all following versions
Okapi v4.13.3 (note that v4.13.x is no longer supported and has reached its end of life)
Okapi v4.14.8 and all following versions
Using the latest v4.14.x Okapi version is recommended for Morning Glory and Nolana.

Best

  Julian Ladisch