Skip to content

Conversation

@amitkarsale
Copy link
Contributor

Bump OpenSSL version to 3.0.14 to fix followingCVE's : CVE-2024-4741 CVE-2024-4603 CVE-2024-2511

@amitkarsale amitkarsale requested review from a team as code owners June 21, 2024 04:48
Copy link
Collaborator

@joshcooper joshcooper left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Could you run vanagon generic builder with agent-runtime-main and all supported build targets from the init job before merging?


# Remove this in 3.0.14 or later
pkg.apply_patch 'resources/patches/openssl/openssl-3.0.13-crypto-providers.patch'

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ah nice!

@joshcooper joshcooper added the bug Something isn't working label Jun 21, 2024
@joshcooper joshcooper changed the title (PUP-12048) Bump openssl version to 3.0.14 (PUP-12048) Update openssl 3.0.14 for CVE-2024-4741, CVE-2024-4603, CVE-2024-2511 Jun 21, 2024
@joshcooper joshcooper merged commit a39b23b into puppetlabs:master Jun 21, 2024
@amitkarsale
Copy link
Contributor Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants