|
Appweb reported an unspecified security issue in their 3.3.3 release. With this announcement, the changelog mentioned changes related to the SSL_OP_NO_TICKET and SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION options. Combined with a long list of SSL renegotiation vulnerabilities over the last two years, OSVDB interpreted this to mean the application was also vulnerability. The vendor has since clarified that OpenSSL does not ship with Appweb, and that these are preventative controls to help users avoid issues when they install an SSL package of their choice. As such, this is an invalid issue.
|