OpenSSL Vulnerability: What You Need to Know

OpenSSL Vulnerability: What You Need to Know

Posted on November 01, 2022 0 Comments

On November 1, 2022, The OpenSSL Foundation released OpenSSL version 3.0.7. This release is a security-fix and addresses two “High” severity vulnerabilities, https://www.openssl.org/news/vulnerabilities.html. Advanced notice was shared by the OpenSSL Foundation last week, alerting the industry of the vulnerability and upcoming patch.

At Progress, security is a top priority. Upon notification, we conducted a thorough review of the Progress product portfolio, and our internal diligence indicates that our products are not using the impacted version of OpenSSL as shipped and/or deployed. We do, however, recommend that customers conduct their own due diligence with respect to any third-party components that may be utilized in their environments and take the appropriate actions recommended by those third parties.

We will continue to closely monitor the OpenSSL vulnerability and provide updates on the Progress Security Center as necessary. For additional questions regarding this message, you may contact security@progress.com and we will quickly address those questions or concerns.

For more information regarding our security practices and privacy posture, please visit our Security Center and Privacy Center.

The Progress Security Team

View all posts from The Progress Security Team on the Progress blog. Connect with us about all things application development and deployment, data integration and digital business.

Comments

Comments are disabled in preview mode.
Topics

Sitefinity Training and Certification Now Available.

Let our experts teach you how to use Sitefinity's best-in-class features to deliver compelling digital experiences.

Learn More
Latest Stories
in Your Inbox

Subscribe to get all the news, info and tutorials you need to build better business apps and sites

Loading animation