CVE-2021-3712: Out-of-bounds Read
(updated )
If a malicious actor can cause an application to directly construct an ASN1_STRING
and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext)
References
Detect and mitigate CVE-2021-3712 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →