KB Article #182305

OpenSSL CVE CVE-2022-2274

Problem

-- Is API Gateway vulnerable to OpenSSL CVE CVE-2022-2274?

https://nvd.nist.gov/vuln/detail/CVE-2022-2274

Resolution

* API Gateway is not vulnerable.

* The CVE is only valid for OpenSSL 3.0.4

API Gateway May 22 release includes OpenSSL 3.0.3

A{I Gateway August 22 release includes OpenSSL 3.0.5

https://www.openssl.org/news/openssl-3.0-notes.htm...