Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1xZjg3LXE0Z2ctY2c0M84AAxgj
bottlerocket dependency openssl is vulnerable to dereferenced null pointers
A null pointer in OpenSSL can be dereferenced when signatures are being verified in malformed PKCS7 data. Agents or clients compiled with OpenSSL may experience unexpected crashes. OpenSSL has been removed in bottlerocket/update-operator version 1.1.0 in favor of Rust-based TLS using rustls.
Permalink: https://github.com/advisories/GHSA-qf87-q4gg-cg43JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xZjg3LXE0Z2ctY2c0M84AAxgj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 8 months ago
Identifiers: GHSA-qf87-q4gg-cg43
References:
- https://github.com/bottlerocket-os/bottlerocket-update-operator/security/advisories/GHSA-qf87-q4gg-cg43
- https://github.com/bottlerocket-os/bottlerocket-update-operator/releases/tag/v1.1.0
- https://www.openssl.org/news/secadv/20230207.txt
- https://github.com/advisories/GHSA-qf87-q4gg-cg43
Blast Radius: 1.0
Affected Packages
cargo:bottlerocket/update-operator
Affected Version Ranges: < 1.1.0Fixed in: 1.1.0