PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/f3991da3.0509bf75.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:43:08 UTC 6,787 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["14952"],{241706:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>l,toc:()=>d,default:()=>h,metadata:()=>n,assets:()=>c,contentTitle:()=>a});var n=JSON.parse('{"id":"security-bulletins/reports/pc-cve-2023-0401","title":"CVE-2023-0401","description":"Lifecycle of CVE-2023-0401","source":"@site/docs/docs-content/security-bulletins/reports/pc-cve-2023-0401.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/pc-cve-2023-0401","permalink":"/security-bulletins/reports/pc-cve-2023-0401","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/pc-cve-2023-0401.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2023-0401","title":"CVE-2023-0401","description":"Lifecycle of CVE-2023-0401","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2023-0361","permalink":"/security-bulletins/reports/pc-cve-2023-0361"},"next":{"title":"CVE-2023-0464","permalink":"/security-bulletins/reports/pc-cve-2023-0464"}}'),s=i(474848),r=i(884429);let l={sidebar_label:"CVE-2023-0401",title:"CVE-2023-0401",description:"Lifecycle of CVE-2023-0401",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},a,c={},d=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,s.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-0401",children:"CVE-2023-0401"})," to learn more."]}),"\n",(0,s.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,s.jsx)(t.p,{children:"10/25/2024"}),"\n",(0,s.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,s.jsx)(t.p,{children:"01/20/2025"}),"\n",(0,s.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,s.jsx)(t.p,{children:"openssl"}),"\n",(0,s.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,s.jsx)(t.p,{children:"A NULL pointer can be dereferenced when signatures are being\nverified on PKCS7 signed or signedAndEnveloped data. In case the hash\nalgorithm used for the signature is known to the OpenSSL library but\nthe implementation of the hash algorithm is not available the digest\ninitialization will fail. There is a missing check for the return\nvalue from the initialization function which later leads to invalid\nusage of the digest API most likely leading to a crash."}),"\n",(0,s.jsx)(t.p,{children:"The unavailability of an algorithm can be caused by using FIPS\nenabled configuration of providers or more commonly by not loading\nthe legacy provider."}),"\n",(0,s.jsx)(t.p,{children:"PKCS7 data is processed by the SMIME library calls and also by the\ntime stamp (TS) library calls. The TLS implementation in OpenSSL does\nnot call these functions however third party applications would be\naffected if they call these functions to verify signatures on untrusted\ndata."}),"\n",(0,s.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-0401",children:"7.5"})}),"\n",(0,s.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,s.jsx)(t.p,{children:"A NULL pointer vulnerability was found in OpenSSL, which can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. There is a missing check for the return\nvalue from the initialization function which later leads to invali
1d usage of the digest API, most likely leading to a crash."}),"\n",(0,s.jsx)(t.p,{children:"The images where this vulnrability is have controls in place are not accessible outside the cluster. So the attacker needs to gain privileged access to the cluster to attempt this exploit. Also\nthe containers do not allow execution of arbitrary code. Impact of this exploit is also low, since container reduces the attack surface."}),"\n",(0,s.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,s.jsx)(t.p,{children:"Ongoing"}),"\n",(0,s.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Version"}),(0,s.jsx)(t.th,{children:"Palette Enterprise"}),(0,s.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,s.jsx)(t.th,{children:"VerteX"}),(0,s.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,s.jsxs)(t.tbody,{children:[(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.5.20"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u2705 No Impact"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u2705 No Impact"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.4.20"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u2705 No Impact"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u2705 No Impact"})]})]})]}),"\n",(0,s.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,s.jsx)(t.p,{children:"No revisions available."})]})}function h(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>l,x:()=>a});var n=i(296540);let s={},r=n.createContext(s);function l(e){let t=n.useContext(r);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:l(e.components),n.createElement(r.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.