1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["14170"],{610349:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>c,toc:()=>a,default:()=>h,metadata:()=>s,assets:()=>d,contentTitle:()=>l});var s=JSON.parse('{"id":"security-bulletins/reports/pc-cve-2023-0464","title":"CVE-2023-0464","description":"Lifecycle of CVE-2023-0464","source":"@site/docs/docs-content/security-bulletins/reports/pc-cve-2023-0464.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/pc-cve-2023-0464","permalink":"/security-bulletins/reports/pc-cve-2023-0464","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/pc-cve-2023-0464.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2023-0464","title":"CVE-2023-0464","description":"Lifecycle of CVE-2023-0464","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2023-0401","permalink":"/security-bulletins/reports/pc-cve-2023-0401"},"next":{"title":"CVE-2023-0767","permalink":"/security-bulletins/reports/pc-cve-2023-0767"}}'),n=i(474848),r=i(884429);let c={sidebar_label:"CVE-2023-0464",title:"CVE-2023-0464",description:"Lifecycle of CVE-2023-0464",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},l,d={},a=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,r.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,n.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,n.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-0464",children:"CVE-2023-0464"})," to learn more."]}),"\n",(0,n.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,n.jsx)(t.p,{children:"10/25/2024"}),"\n",(0,n.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,n.jsx)(t.p,{children:"04/23/2026"}),"\n",(0,n.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,n.jsx)(t.p,{children:"openssl"}),"\n",(0,n.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,n.jsx)(t.p,{children:"A security vulnerability has been identified in all supported versions"}),"\n",(0,n.jsx)(t.p,{children:"of OpenSSL related to the verification of X.509 certificate chains\nthat include policy constraints. Attackers may be able to exploit this\nvulnerability by creating a malicious certificate chain that triggers\nexponential use of computational resources, leading to a denial-of-service\n(DoS) attack on affected systems."}),"\n",(0,n.jsx)(t.p,{children:"Policy processing is disabled by default but can be enabled by passing\nthe `-policy' argument to the command line utilities or by calling the\n`X509_VERIFY_PARAM_set1_policies()' function."}),"\n",(0,n.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,n.jsx)(t.p,{children:(0,n.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2023-0464",children:"7.5"})}),"\n",(0,n.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,n.jsxs)(t.p,{children:["This is a false positive reported by twistlock. We have confirmed this CVE is fixed in the FIPS openSSL version\n1.1.1f-1ubuntu2.fips.22 that\u2019s being used in VerteX. You can learn more about this CVE at\n",(0,n.jsx)(t.a,{href:"https://ubuntu.com/security/CVE-2023-0464",children:"https://ubuntu.com/security/CVE-2023-0464"}),"."]}),"\n",(0,n.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,n.jsx)(t.p,{children:"Ongoing"}),"\n",(0,n.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,n.jsxs)(t.table,{children:[(0,n.jsx)(t.thead,{children:(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.th,{children:"Version"}),(0,n.jsx)(t.th,{children:"Palette Enterprise"}),(0,n.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,n.jsx)(t.th,{children:"VerteX"}),(0,n.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,n.jsxs)(t.tbody,{children:[(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.8.52"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.7.29"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.6.41"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.5.22"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.4.20"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,n.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,n.jsx)(t.p,{children:"No revisions available."})]})}function h(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>c,x:()=>l});var s=i(296540);let n={},r=s.createContext(n);function c(e){let t=s.useContext(r);return s.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function l(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:c(e.components),s.createElement(r.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.