New OpenSSL 3.0 vulnerabilities: What you need to know to find and fix them
Blog post from GitLab
OpenSSL has identified two vulnerabilities, CVE-2022-3786 and CVE-2022-3602, impacting versions 3.0 to 3.0.6, which relate to X.509 email address buffer overflows that could lead to denial of service or, under certain conditions, remote code execution. These vulnerabilities, originally considered critical but later downgraded to high, can be mitigated by upgrading to OpenSSL 3.0.7, which includes necessary patches. The vulnerabilities stem from punycode decoding in X.509 certificates, first introduced in OpenSSL 3.0.0, and do not affect earlier versions like 1.0.2 and 1.1.1. Organizations using OpenSSL 3.0 should assess their software supply chain's exposure using tools like GitLab's dependency and container scanning. GitLab has confirmed that its production systems remain unaffected, though it has updated its DAST analyzer to address the issue. It is advised for organizations to upgrade to OpenSSL 3.0.7 to secure their systems against these vulnerabilities.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.