Website Security & Threat Management
Cloudflare is not affected by the OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786

Cloudflare is not affected by the OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786

11/2/2022 · Evan Johnson, Michal Melewski

What this post added

This post details how Cloudflare's adoption of BoringSSL, rather than OpenSSL, renders it unaffected by critical OpenSSL vulnerabilities CVE-2022-3602 and CVE-2022-3786. It explains the nature of these vulnerabilities, their potential impact on clients and servers, and provides guidance on patching vulnerable OpenSSL instances. The key takeaway is Cloudflare's proactive security stance through its choice of cryptographic library.

Read the original post ↗