Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

New OpenSSL 3.0 vulnerabilities: What you need to know to find and fix them

Blog post from GitLab

Post Details
Company
Date Published
Author
GitLab Security Team
Word Count
502
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

OpenSSL has identified two vulnerabilities, CVE-2022-3786 and CVE-2022-3602, impacting versions 3.0 to 3.0.6, which relate to X.509 email address buffer overflows that could lead to denial of service or, under certain conditions, remote code execution. These vulnerabilities, originally considered critical but later downgraded to high, can be mitigated by upgrading to OpenSSL 3.0.7, which includes necessary patches. The vulnerabilities stem from punycode decoding in X.509 certificates, first introduced in OpenSSL 3.0.0, and do not affect earlier versions like 1.0.2 and 1.1.1. Organizations using OpenSSL 3.0 should assess their software supply chain's exposure using tools like GitLab's dependency and container scanning. GitLab has confirmed that its production systems remain unaffected, though it has updated its DAST analyzer to address the issue. It is advised for organizations to upgrade to OpenSSL 3.0.7 to secure their systems against these vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.