# Elastic Security Statement for OpenSSL CVE-2022-3786 and CVE-2022-3602, OpenSSL version 3.0.7

**URL:** <https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039>\
**Category:** Security Announcements\
**Created:** [November 2, 2022, 6:41pm UTC](https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039 "2022-11-02T18:41:00Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![Levine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/levine/32/94697_2.png) [@Levine](https://discuss.elastic.co/u/Levine)\
**Post date:** [November 2, 2022, 6:41pm UTC](https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039/1 "2022-11-02T18:41:01Z")

</div>

**Elastic Products are not affected by this issue.**

On Oct 25, 2022, Elastic became aware of the [Forthcoming OpenSSL 3.0.7 Release announcement](https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html), which was made available on Nov 1, 2022. The security issues addressed in this release do not affect OpenSSL versions before 3.0.

Elastic has performed an investigation to identify any Elastic Products which may be impacted by this issue and we have concluded that no Elastic products use the versions of OpenSSL affected by these vulnerabilities. Therefore, Elastic Products are not affected by this issue.

Reference Links:

- [CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows - OpenSSL Blog](https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/)
- [https://www.openssl.org/news/secadv/20221101.txt](https://www.openssl.org/news/secadv/20221101.txt)
- [NVD - CVE-2022-3786](https://nvd.nist.gov/vuln/detail/CVE-2022-3786)
- [NVD - CVE-2022-3602](https://nvd.nist.gov/vuln/detail/CVE-2022-3602)
- [Forthcoming OpenSSL Releases](https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html)

---

_[View the full topic](https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039)._
