GHSA-qf87-q4gg-cg43

Suggest an improvement
Source
https://github.com/advisories/GHSA-qf87-q4gg-cg43
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-qf87-q4gg-cg43/GHSA-qf87-q4gg-cg43.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qf87-q4gg-cg43
Published
2023-02-09T19:33:13Z
Modified
2023-02-09T19:33:13Z
Summary
bottlerocket dependency openssl is vulnerable to dereferenced null pointers
Details

A null pointer in OpenSSL can be dereferenced when signatures are being verified in malformed PKCS7 data. Agents or clients compiled with OpenSSL may experience unexpected crashes. OpenSSL has been removed in bottlerocket/update-operator version 1.1.0 in favor of Rust-based TLS using rustls.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2023-02-09T19:33:13Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": []
}
References

Affected packages

crates.io / bottlerocket/update-operator

Package

Name
bottlerocket/update-operator
View open source insights on deps.dev
Purl
pkg:cargo/bottlerocket/update-operator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.0