openssl-fips-provider #14019
-
Version2.4.60 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsMeets minimum requirements CPU4 RAM24 Storage for /100 Storage for /nsm215 Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailOur vulnerability scanners are reporting that there is a vulnerability present in the installed version of "openssl-fips-provider" in our SecurityOnion servers. We have reviewed, and the reported version numbers appear to be correct. The updated version does not appear to be available in the update repository. The Oracle reference number for the vulnerability is ELSA-2024-9333. Installed version: openssl-fips-provider-3.0.7-2.0.1.el9 Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 11 replies
-
I see that the updated openssl that also had a CVE was pulled down on Dec. 1st. We were not explicitly pulling openssl-fips-provider down since its a dependency of systemd. I tried to install the version that is mentioned in the CVE manually, but systemd blocked it. It will have to wait until systemd is updated for it to actually install. |
Beta Was this translation helpful? Give feedback.
-
This has been resolved:
|
Beta Was this translation helpful? Give feedback.
This has been resolved: