
11/1/2022 · GitLab Security Team
What this post added
This post details the discovery and mitigation of specific X.509 email address buffer overflow vulnerabilities (CVE-2022-3786 and CVE-2022-3602) in OpenSSL 3.0, emphasizing the need to upgrade to OpenSSL 3.0.7 and how GitLab's dependency scanning and DAST analyzer were used to assess and patch the vulnerability within its own systems.