SSL/TLS Security Enhancements
New OpenSSL 3.0 vulnerabilities: What you need to know to find and fix them

New OpenSSL 3.0 vulnerabilities: What you need to know to find and fix them

11/1/2022 · GitLab Security Team

What this post added

This post details the discovery and mitigation of specific X.509 email address buffer overflow vulnerabilities (CVE-2022-3786 and CVE-2022-3602) in OpenSSL 3.0, emphasizing the need to upgrade to OpenSSL 3.0.7 and how GitLab's dependency scanning and DAST analyzer were used to assess and patch the vulnerability within its own systems.

Read the original post ↗