HIGH
GHSA-qf87-q4gg-cg43
bottlerocket dependency openssl is vulnerable to dereferenced null pointers
Details
A null pointer in OpenSSL can be dereferenced when signatures are being verified in malformed PKCS7 data. Agents or clients compiled with OpenSSL may experience unexpected crashes. OpenSSL has been removed in bottlerocket/update-operator version 1.1.0 in favor of Rust-based TLS using rustls.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/bottlerocket/update-operator
Introduced in:
0Fixed in: 1.1.0Upgrade bottlerocket/update-operator to 1.1.0 or newer (ecosystem crates.io).
References
- https://github.com/bottlerocket-os/bottlerocket-update-operator/security/advisories/GHSA-qf87-q4gg-cg43[WEB]
- https://github.com/bottlerocket-os/bottlerocket-update-operator[PACKAGE]
- https://github.com/bottlerocket-os/bottlerocket-update-operator/releases/tag/v1.1.0[WEB]
- https://www.openssl.org/news/secadv/20230207.txt[WEB]