Best Answer

OpenSSL 3.0 Vulnerabilities

  • 9 November 2022
  • 3 replies
  • 55 views

I’m looking for information on whether your organization is aware of the OpenSSL 3.0 vulnerabilities disclosed earlier this month, summarized in CVE-2022-3602 and CVE-2022-3786.  If so, have you investigated whether any of your internal systems are vulnerable and have you mitigated those vulnerabilities if they exist?

Thank you!

icon

Best answer by John 14 November 2022, 19:01

View original

3 replies

Userlevel 5
Badge +2

@sgaucher - please see below for a recent response from our InfoSec and Product teams, in re: to the vulnerabilities you’ve mentioned:

OpenSSL Security Advisory (CVE-2022-3786 and CVE-2022-3602)

Docebo is not affected by the reported vulnerabilities in our product since the affected versions of the software are not used in any part of the product infrastructure.

Awesome, thanks John!

Userlevel 5
Badge +2

You are most welcome! 

Reply