Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

#94 OpenSSL #102

Closed
joaoluis-pdm opened this issue Jul 28, 2022 · 2 comments
Closed

#94 OpenSSL #102

joaoluis-pdm opened this issue Jul 28, 2022 · 2 comments
Assignees
Labels
bug Something isn't working

Comments

@joaoluis-pdm
Copy link
Contributor

From #94

List of Container Packages with HIGH CVEs

Container Packages detected

HIGH - openssl

(RECURRENT) GHSA-497c-86pp-222m: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).

@joaoluis-pdm joaoluis-pdm added the bug Something isn't working label Jul 28, 2022
@joaoluis-pdm joaoluis-pdm self-assigned this Jul 28, 2022
@joaoluis-pdm
Copy link
Contributor Author

OpenSSL is required for nodejs to be able to open https connections to other anchoring and bricking services.

Checking current openssl version in use as of v0.10.2.

@joaoluis-pdm
Copy link
Contributor Author

Since v0.9.5 openssl is not in use. ssl_client is in use instead. Issue closed,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant