AFP Security Warning

Kris Moore

SVP of Engineering
Administrator
Moderator
iXsystems
Joined
Nov 12, 2015
Messages
1,471
Just a heads up today for any of our users still running AFP in production. Some critical CVE's have been announced which makes running AFP potentially dangerous for TrueNAS CORE and Enterprise systems (SCALE is NOT impacted, due to AFP being removed). We are working on updates and fixes in the background, however due to the deprecated nature and age of the netatalk (AFP Server) code, this will take some time. In the meantime, this is a good reminder to finish migrating any of your legacy AFP shares over to SMB to make your TrueNAS safe from these potential issues.

https://www.truenas.com/docs/releasenotes/core/12.0u8/#known-issues
https://security.truenas.com/articles/2022-04-08-netatalk/
 
Top