Skip to content

Bump puppet-agent's bundled openssl to address CVE-2024-5535 #872

@cthorn42

Description

@cthorn42

Details are listed here: https://www.openssl.org/news/secadv/20240627.txt
Highlights are:

  • rated low
  • haven't released a fix yet

Puppet-agent 7.31.0 has OpenSSL version 1.1.1v (patched of course) and puppet-agent 8.7.0 has OpenSSl version 3.0.13. When a fix for this CVE is released we should patch the former and upgrade the later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriagedJira issue has been created for this

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions