Skip to main content
Version: latest

CVE-2023-0464

CVE Details

CVE-2023-0464

Last Update

8/16/2024

NIST CVE Summary

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints.

Our Official Summary

This is a false positive reported by twistlock. We have confirmed this CVE is fixed in the FIPS openSSL version 1.1.1f-1ubuntu2.fips.22 that’s being used in VerteX. You can learn more about this CVE at https://ubuntu.com/security/CVE-2023-0464.

CVE Severity

7.5

Status

Ongoing

Affected Products & Versions

  • Palette VerteX 4.4.11
  • Palette VerteX 4.4.14

Revision History

  • 1.0 07/16/2024 Initial Publication
  • 2.0 08/16/2024 Added palette VerteX 4.4.14 to Affected Products