Insecure digital certificates In bottlerocket/update-operator
Description
bottlerocket dependency openssl is vulnerable to dereferenced null pointers A null pointer in OpenSSL can be dereferenced when signatures are being verified in malformed PKCS7 data. Agents or clients compiled with OpenSSL may experience unexpected crashes. OpenSSL has been removed in bottlerocket/update-operator version 1.1.0 in favor of Rust-based TLS using rustls.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
cargo | 1.1.0 |
Aliases
1. 2. 3.
References
1. 2. 3.