{"id":"GHSA-j859-pmrq-9q6c","summary":"bottlerocket dependency openssl has a double free vulnerability","details":"A timing based side channel exists in the OpenSSL RSA decryption implementation which could enable a recovery of plaintext from across the network.  This affects all RSA padding modes. A server agent compiled with OpenSSL could be made to give up plaintext payloads over the network, but this would require a large amount of malicious payloads from a third party actor as trial messages. OpenSSL removed in bottlerocket version 1.1.0 in favor of Rust-based TLS using rustls.","modified":"2023-02-09T19:32:29Z","published":"2023-02-09T19:32:29Z","database_specific":{"cwe_ids":[],"github_reviewed_at":"2023-02-09T19:32:29Z","github_reviewed":true,"nvd_published_at":null,"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator/security/advisories/GHSA-j859-pmrq-9q6c"},{"type":"PACKAGE","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator"},{"type":"WEB","url":"https://github.com/bottlerocket-os/bottlerocket-update-operator/releases/tag/v1.1.0"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0007.html"},{"type":"WEB","url":"https://www.openssl.org/news/secadv/20230207.txt"}],"affected":[{"package":{"name":"bottlerocket/update-operator","ecosystem":"crates.io","purl":"pkg:cargo/bottlerocket/update-operator"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-j859-pmrq-9q6c/GHSA-j859-pmrq-9q6c.json"}}],"schema_version":"1.7.3"}