Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DataDog Agent v7.50.0 still contains OpenSSL 3.0.8 dll's with known vulnerabilties #21678

Open
RoelofRoelofsen opened this issue Dec 20, 2023 · 3 comments

Comments

@RoelofRoelofsen
Copy link

In the release notes (security notes) of version 7.50.0 I found updated OpenSSL from 3.0.11 to 3.0.12.

MIcrosoft Defender still found OpenSSL dll's with version 3.0.8 with known vulnerabilties in the DataDog Agent application folders (C:\Program Files\Datadog\Datadog Agent\embedded3\Lib\site-packages\confluent_kafka.libs).

@toucheDD
Copy link

toucheDD commented May 1, 2024

This is still not fixed in newest versions. 7.52.1 nor 7.53.0?
Is it even being considered to be fixed?

@smerkx
Copy link

smerkx commented Jun 13, 2024

Also not fixed in 7.54.0. Defender alerts on:
3.0.13.0:
c:\program files\datadog\datadog agent\embedded3\dlls\libcrypto-3.dll
c:\program files\datadog\datadog agent\embedded3\dlls\libssl-3.dll

3.0.8.0:
c:\program files\datadog\datadog agent\embedded3\lib\site-packages\confluent_kafka.libs\libcrypto-3-x64-635e87f2c9173c8128924a94337627b3.dll
c:\program files\datadog\datadog agent\embedded3\lib\site-packages\confluent_kafka.libs\libssl-3-x64-a0018292260ae8557aa3cd7db7d50307.dll

@smerkx
Copy link

smerkx commented Sep 2, 2024

Release notes for 7.56.0 say:
Security Notes:

Updated all agents to 7.56.0, but that still installs openssl 3.0.13 dlls in c:\program files\datadog\datadog agent\embedded3\dlls

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants