Security

Voltar para Security Alert

Elastic Stack and Liferay Enterprise Search Security Advisory: Security Statement for OpenSSL CVE-2022-3786 and CVE-2022-3602, OpenSSL version 3.0.7

This advisory was created to share Elastic's security statement issued for the Oracle July Critical Patch Update recently.

Elastic's Statement

Elastic Products are not affected by this issue.

On Oct 25, 2022, Elastic became aware of the Forthcoming OpenSSL 3.0.7 Release announcement 4, which was made available on Nov 1, 2022. The security issues addressed in this release do not affect OpenSSL versions before 3.0.

Elastic has performed an investigation to identify any Elastic Products which may be impacted by this issue and we have concluded that no Elastic products use the versions of OpenSSL affected by these vulnerabilities. Therefore, Elastic Products are not affected by this issue.

Reference Links:

Source

https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039


Elastic, Elasticsearch, and X-Pack are trademarks of Elasticsearch BV, registered in the U.S. and in other countries.

On this page