<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenSSL CVE-2023-5678 in Dynatrace Managed Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240174#M3249</link>
    <description>&lt;P&gt;No, you shall not remove those files.&lt;BR /&gt;&lt;BR /&gt;As stated above - Managed is not affected as it is not using the vulnerable code in this CVE.&amp;nbsp; If you are still in doubt, reach out to Dynatrace as described here:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/managed/shortlink/who-to-contact-security" target="_blank"&gt;https://docs.dynatrace.com/managed/shortlink/who-to-contact-security&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2024 08:11:56 GMT</pubDate>
    <dc:creator>Julius_Loman</dc:creator>
    <dc:date>2024-03-18T08:11:56Z</dc:date>
    <item>
      <title>OpenSSL CVE-2023-5678</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240143#M3246</link>
      <description>&lt;P&gt;Tenable flag a medium vulnerability - &lt;A href="https://www.tenable.com/cve/CVE-2023-5678" target="_blank"&gt;https://www.tenable.com/cve/CVE-2023-5678&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;From Dynatrace official community post on CVE-2023-5678 was posted months back.&lt;/P&gt;&lt;P&gt;Quote: "Not affected. Vulnerable library is part of the base image"&lt;/P&gt;&lt;P&gt;Affected library: OpenSSL (1.0.2 - &amp;lt;1.0.2zj, 1.1.0-&amp;lt;1.1.1x, 3.0.0-&amp;lt;3.0.13, 3.1.0-&amp;lt;3.1.05)&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.dynatrace.com/t5/Heads-up-from-Dynatrace/Dynatrace-CVE-status-Common-Vulnerabilities-and-Exposures/ta-p/214793" target="_blank"&gt;https://community.dynatrace.com/t5/Heads-up-from-Dynatrace/Dynatrace-CVE-status-Common-Vulnerabilities-and-Exposures/ta-p/214793&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In recent Dynatrace Managed version 1.286. Dynatrace actually went to update the OpenSSL to 1.1.1w. One version below x.&lt;/P&gt;&lt;P&gt;What baffles us is as follows&lt;/P&gt;&lt;P&gt;1) Since this is to Dynatrace not affected. Why would they upgrade to 1.1.1w?&lt;/P&gt;&lt;P&gt;2) And why wouldnt they go straight to 1.1.1x instead of 1.1.1w&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3) We even ask if we could remove the flagged file since we were told its part of the base image but were told there are dependecies.&lt;/P&gt;&lt;P&gt;Path - /usr/opt/dynatrace-managed/installer/bin/libssl.so.1.1&lt;BR /&gt;Path - /usr/opt/dynatrace-managed/installer/bin/libcrypto.so.1.1&lt;/P&gt;&lt;P&gt;Path - /usr/install/_DTTMP_20230418_092419/bin/libssl.so.1.1&lt;BR /&gt;Path - /usr/install/_DTTMP_20230418_092419/bin/libcrypto.so.1.1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Could anyone enlighten us based on your expereience with Dynatrace? Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 06:45:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240143#M3246</guid>
      <dc:creator>Suryanto_1</dc:creator>
      <dc:date>2024-03-18T06:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL CVE-2023-5678</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240159#M3247</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/66727"&gt;@Suryanto_1&lt;/a&gt;&amp;nbsp; you are looking at a different component in the list of CVEs.&lt;BR /&gt;&lt;BR /&gt;For Managed it's further down in the list:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Julius_Loman_0-1710747308257.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18335i14DC24539ACAE23B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Julius_Loman_0-1710747308257.png" alt="Julius_Loman_0-1710747308257.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 07:35:40 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240159#M3247</guid>
      <dc:creator>Julius_Loman</dc:creator>
      <dc:date>2024-03-18T07:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL CVE-2023-5678</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240164#M3248</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;We even ask if we could remove the flagged file (below) as clealy the path are managed&lt;/P&gt;&lt;P&gt;However we were told its part of the base image and there are dependencies so its NOT recommended to remove!&lt;/P&gt;&lt;P&gt;Path - /usr/opt/dynatrace-managed/installer/bin/libssl.so.1.1&lt;BR /&gt;Path - /usr/opt/dynatrace-managed/installer/bin/libcrypto.so.1.1&lt;/P&gt;&lt;P&gt;Path - /usr/install/_DTTMP_20230418_092419/bin/libssl.so.1.1&lt;BR /&gt;Path - /usr/install/_DTTMP_20230418_092419/bin/libcrypto.so.1.1&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 07:39:26 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240164#M3248</guid>
      <dc:creator>Suryanto_1</dc:creator>
      <dc:date>2024-03-18T07:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSL CVE-2023-5678</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240174#M3249</link>
      <description>&lt;P&gt;No, you shall not remove those files.&lt;BR /&gt;&lt;BR /&gt;As stated above - Managed is not affected as it is not using the vulnerable code in this CVE.&amp;nbsp; If you are still in doubt, reach out to Dynatrace as described here:&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/managed/shortlink/who-to-contact-security" target="_blank"&gt;https://docs.dynatrace.com/managed/shortlink/who-to-contact-security&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:11:56 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/OpenSSL-CVE-2023-5678/m-p/240174#M3249</guid>
      <dc:creator>Julius_Loman</dc:creator>
      <dc:date>2024-03-18T08:11:56Z</dc:date>
    </item>
  </channel>
</rss>

