Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Will upgrade openSSL to 3.0.9? #47443 #113

Closed
puremdq opened this issue Apr 13, 2023 · 5 comments
Closed

[Question] Will upgrade openSSL to 3.0.9? #47443 #113

puremdq opened this issue Apr 13, 2023 · 5 comments

Comments

@puremdq
Copy link

puremdq commented Apr 13, 2023

Recently there are several vulnerabilities reported about openSSL (GHSA-w2w6-xp88-5cvw, GHSA-77f3-6546-6rj7, GHSA-pxvj-4wx4-gv6w), these vulnerabilities are fixed in openSSL 3.0.9, will Node.js consider its openSSL to this version? Thanks.

@baparham
Copy link

baparham commented Apr 18, 2023

@tmshort Do you have a plan to bump to 3.0.9 soon or should someone take a shot at making a PR rebasing against the upstream 3.0.9?

[edit: I can now see that 3.0.9 isn't released nor tagged upstream yet, so I suppose it makes perfect sense that this hasn't tracked to that change!]

@tmshort
Copy link
Member

tmshort commented Apr 18, 2023

OpenSSL 3.0.9 doesn't exist yet (has not been announced, has not been tagged), when it is released, QuicTLS will be updated.

@FireMasterK
Copy link

OpenSSL 3.1.0 exists now and is tagged, will we be updating to that instead?

@baparham
Copy link

Apparently 3.1 is not an LTS branch, so node says they won't be upgrading to it, instead waiting for 3.0.9 when it comes out.

@richsalz
Copy link
Member

Our goal is to track the 3.1 and 3.0.x releases. I am closing this issue. Please open a new one if we don't meet the goal.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants