Outbreak Alert: OpenSSL Buffer Overflow Vulnerability
| Description | This article describes OpenSSL X.509 certificate verification buffer overflow vulnerabilities detection with FortiDevSec.
CVE-2022-3602 and CVE-2022-3786 vulnerabilities are 0-day exploits that were discovered on a popular open source library: OpenSSL. Both vulnerabilities are triggered by the X.509 certificate verification code. Those zero-days can result in a crash or potential remote code execution, allowing the attacker to either impact the availability of the service or to get full control of the target. |
| Scope | FortiDevSec Container scanner since version 22.4.a. |
| Solution | Both vulnerabilities are detected by the FortiDevSec Container scanner which is identifying OS packages and open-source dependencies in all container layers provided.
The container scanner is enabled by default.
A step-by-step guide on how to scan your application is available in the user guide.
For more details regarding mtiigating the vulnerability by utilizing Fortinet products, refer to: https://www.fortiguard.com/outbreak-alert/openssl-buffer-overflow |
