openssl-fips-provider part 2 #14763
-
Version2.4.150 Installation MethodSecurity Onion ISO image Descriptionother (please provide detail below) Installation TypeDistributed Locationon-prem with Internet access Hardware SpecsExceeds minimum requirements CPU12 RAM48GB Storage for /1TB Storage for /nsm1TB Network Traffic Collectionspan port Network Traffic Speeds1Gbps to 10Gbps StatusYes, all services on all nodes are running OK Salt StatusNo, there are no failures LogsNo, there are no additional clues DetailI'm getting dinged on my company vul scans for having an out of date openssl-fips-provider package. I checked and the package version the scanner reports is what appears to be on the system. openssl-fips-provider.x86_64 3.0.7-2.0.1.el9 @securityonion I came here to see if anyone had reported this, and found this thread. In this thread the lack of update was blamed on Oracle, which is fair enough, but it's now 6 months later, the thread is locked, but still open, and this vul is now listed as critical by my company. Oracle seems to have updated this package so is there anything else that's holding this up? Guidelines
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
Does anyone know how to read the package list directly from Security Onion? I found the URL but can't seem to open it in a browser like I can with the Oracle repo. |
Beta Was this translation helpful? Give feedback.
-
This has been resolved:
|
Beta Was this translation helpful? Give feedback.
This has been resolved: