Home / Companies / Octopus Deploy / Blog / Post Details
Content Deep Dive

Octopus Deploy's response to the OpenSSL vulnerability

Blog post from Octopus Deploy

Post Details
Company
Date Published
Author
Colby Prior
Word Count
126
Language
English
Hacker News Points
-
Summary

A high severity vulnerability in OpenSSL versions 3.x was announced, but Octopus Deploy is unaffected as it relies on OpenSSL versions 1.x. This vulnerability impacts servers that validate client certificates, a process utilized by Octopus Tentacle to register with the Octopus Deploy Server. However, since Octopus Tentacle uses OpenSSL 1.x, it remains secure from this specific threat. The version in use by Octopus Tentacle is supported until September 11, 2023. Further information about the vulnerability is available on the Datadog blog.