Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical vulnerability CVE-2024-5535 in alpine/openssl 3.1.5-r0 version packaged in curlimages/curl:8.8.0 #60

Closed
barkhachoithani opened this issue Jul 11, 2024 · 5 comments

Comments

@barkhachoithani
Copy link

Critical vulnerability CVE-2024-5535 is fixed in alpine/openssl version 3.1.6-r0 or higher.
Please see https://build.alpinelinux.org/buildlogs/build-3-19-s390x/main/openssl/openssl-3.1.6-r2.log https://security.snyk.io/vuln/SNYK-ALPINE319-OPENSSL-7413523

curl image should be updated with the latest/stable version of alpine/openssl.

@dfandrich
Copy link

dfandrich commented Jul 11, 2024 via email

@bagder
Copy link
Member

bagder commented Jul 11, 2024

Also, curl does not use the affected function so the mentioned OpenSSL CVE cannot be triggered by curl.

@barkhachoithani
Copy link
Author

The OpenSSL project considers this so low a priority that they're not even issuing a new release to fix it. Do you see this as particularly bad problem with curl?

Yes, OpenSSL considers it as low however image scan results says it's critical.
https://scout.docker.com/vulnerabilities/id/CVE-2024-5535/
GHSA-4fc7-mvrr-wv2c.
alpine/openssl has a fix version.

@dfandrich
Copy link

dfandrich commented Jul 11, 2024 via email

@xquery
Copy link
Member

xquery commented Jul 12, 2024

for reasons explained above an out of band release is not needed in this case - this will get fixed when we do the next curl release.

@xquery xquery closed this as completed Jul 12, 2024
@xquery xquery reopened this Jul 12, 2024
@xquery xquery closed this as completed Oct 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants