Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] - OpenSSL 3.0.2. included - with security vulnerability - in Service Fabric deployment #1401

Open
rfcdejong opened this issue Nov 10, 2022 · 1 comment
Assignees
Labels
area-Security Relates to Security subsystem type-code-defect Something isn't working

Comments

@rfcdejong
Copy link

Describe the bug
Microsoft defender shows that OpenSSL is being used within Service Fabric

Having installed runtime 9.1.1390.9590 with SDK 6.1.1390

C:\Program Files\Microsoft Service Fabric\bin\Fabric\Fabric.Code\libcrypto-3-x64.dll
C:\Program Files\Microsoft Service Fabric\bin\Fabric\Fabric.Code\libssl-3-x64.dll

image

It is OpenSSL 3.0.2 being used, not 3.0.7 which contains the fix

Assignees: /cc @microsoft/service-fabric-triage

@rfcdejong rfcdejong added the type-code-defect Something isn't working label Nov 10, 2022
@craftyhouse craftyhouse added the area-Security Relates to Security subsystem label Dec 7, 2022
@bharsaklemukesh975
Copy link

Can I work on this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area-Security Relates to Security subsystem type-code-defect Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants