-
-
Notifications
You must be signed in to change notification settings - Fork 12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Critical vulnerability CVE-2024-5535 in alpine/openssl 3.1.5-r0 version packaged in curlimages/curl:8.8.0 #60
Comments
The OpenSSL project considers this so low a priority that they're not even issuing a new release to fix it. Do you see this as particularly bad problem with curl?
|
Also, curl does not use the affected function so the mentioned OpenSSL CVE cannot be triggered by curl. |
Yes, OpenSSL considers it as low however image scan results says it's critical. |
If curl can't trigger the vulnerability then it's even less than low—it's zero.
|
for reasons explained above an out of band release is not needed in this case - this will get fixed when we do the next curl release. |
Critical vulnerability CVE-2024-5535 is fixed in alpine/openssl version 3.1.6-r0 or higher.
Please see https://build.alpinelinux.org/buildlogs/build-3-19-s390x/main/openssl/openssl-3.1.6-r2.log https://security.snyk.io/vuln/SNYK-ALPINE319-OPENSSL-7413523
curl image should be updated with the latest/stable version of alpine/openssl.
The text was updated successfully, but these errors were encountered: