DevOps Articles

Curated articles, resources, tips and trends from the DevOps World.

Security Advisory: Critical OpenSSL Vulnerability

2 years ago www.docker.com

Summary: This is a summary of an article originally published by the source. Read the full original article here →

The OpenSSL Project will release a security fix (https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html) for a new-and-disclosed CVE on Tuesday, November 1, 2022. Docker estimates about 1,000 image repositories could be impacted across various Docker Official Images and Docker Verified Publisher images.

Docker created a placeholder for the OpenSSL CVE, which we’ll soon replace with the official CVE once it’s disclosed.

And if Docker doesn’t detect a vulnerable version of OpenSSL in your image, you’ll see the following: INFO DSA-2022-0001 not detected

As mentioned earlier, we’ll update this blog once the OpenSSL Project provides more vulnerability details.

Made with pure grit © 2024 Jetpack Labs Inc. All rights reserved. www.jetpacklabs.com