Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Version 1.120.0 Affected by CVE-2024-5535 #7253

Open
aldiaz3137 opened this issue Jul 17, 2024 · 3 comments
Open

Version 1.120.0 Affected by CVE-2024-5535 #7253

aldiaz3137 opened this issue Jul 17, 2024 · 3 comments
Labels
area/dependencies Updates a dependency

Comments

@aldiaz3137
Copy link

Description:

Authenticated vulnerability scans are detecting the latest version as being vulnerable to CVE-2024-5535 related to OpenSSL verison 1.1.1w.

Tenable Nessus Agent reports the following:

Path : /usr/local/aws-sam-cli/dist/_internal/libcrypto.so.1.1
Reported version : 1.1.1w
Fixed version : 1.1.1za

Path : /usr/local/aws-sam-cli/dist/_internal/libssl.so.1.1
Reported version : 1.1.1w
Fixed version : 1.1.1za

@aldiaz3137 aldiaz3137 added the stage/needs-triage Automatically applied to new issues and PRs, indicating they haven't been looked at. label Jul 17, 2024
@jysheng123
Copy link
Contributor

Thanks for bringing this up to our attention, we are now in the process of bumping our teams openSSL version. Thanks

@jysheng123 jysheng123 added area/dependencies Updates a dependency and removed stage/needs-triage Automatically applied to new issues and PRs, indicating they haven't been looked at. labels Jul 18, 2024
@hnnasit
Copy link
Contributor

hnnasit commented Sep 10, 2024

OpenSSL version was bumped to 3.3.1 in the SAM CLI version 1.122.0. Closing as the CVE has been fixed.

@hnnasit hnnasit closed this as completed Sep 10, 2024
Copy link
Contributor

⚠️COMMENT VISIBILITY WARNING⚠️

Comments on closed issues are hard for our team to see.
If you need more assistance, please either tag a team member or open a new issue that references this one.
If you wish to keep having a conversation with other community members under this issue feel free to do so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/dependencies Updates a dependency
Projects
None yet
Development

No branches or pull requests

4 participants