Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSsl version update for vulnerability #2820

Open
apop5 opened this issue Aug 28, 2024 · 1 comment
Open

OpenSsl version update for vulnerability #2820

apop5 opened this issue Aug 28, 2024 · 1 comment
Labels
security An issue that impacts security

Comments

@apop5
Copy link

apop5 commented Aug 28, 2024

cryptography 38.0.4 is consumed in https://github.com/DMTF/libspdm/tree/main/os_stub/openssllib

This is being flagged due to known vulerabilities:

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

The recommendation is to upgrade cryptography from 38.0.4 to 42.0.0 to fix the vulnerability.

@steven-bellock steven-bellock added the security An issue that impacts security label Aug 29, 2024
steven-bellock added a commit to steven-bellock/libspdm that referenced this issue Aug 29, 2024
Fix DMTF#2820.

Signed-off-by: Steven Bellock <sbellock@nvidia.com>
@steven-bellock
Copy link
Contributor

@jyao1 you might have to take this. I'm getting errors when running https://github.com/DMTF/libspdm/blob/main/os_stub/openssllib/process_files.pl

@apop5 apop5 changed the title OpenSsl version update ot OpenSsl version update for vulnerability Aug 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security An issue that impacts security
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants