# CVE-2021-3450 in foundationdb 6.2.30

**URL:** <https://forums.foundationdb.org/t/cve-2021-3450-in-foundationdb-6-2-30/2847>\
**Category:** Using FoundationDB\
**Created:** [August 11, 2021, 2:21pm UTC](https://forums.foundationdb.org/t/cve-2021-3450-in-foundationdb-6-2-30/2847 "2021-08-11T14:21:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuk](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@tuk](https://forums.foundationdb.org/u/tuk)\
**Post date:** [August 11, 2021, 2:21pm UTC](https://forums.foundationdb.org/t/cve-2021-3450-in-foundationdb-6-2-30/2847/1 "2021-08-11T14:21:14Z")

</div>

In our app-check, foundationdb (`fdbcli`, `fdbserver` and `backup_agent`) is getting flagged for [CVE-2021-3450](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3450) . It appears this CVE is addressed in OpenSSL 1.1.1k.

Can someone let me know if foundationdb is really affected by this CVE or is there an open issue to upgrade OpenSSL to 1.1.k?

---

<div class="post-metadata">

**Author:** ![alexmiller](https://sea1.discourse-cdn.com/foundationdb/user_avatar/forums.foundationdb.org/alexmiller/32/326_2.png) [@alexmiller](https://forums.foundationdb.org/u/alexmiller)\
**Post date:** [August 12, 2021, 6:29pm UTC](https://forums.foundationdb.org/t/cve-2021-3450-in-foundationdb-6-2-30/2847/2 "2021-08-12T18:29:44Z")

</div>

It looks like 6.2.30 was compiled against openssl-1.1.1h [foundationdb/Dockerfile at c1acf5fc16a522b0f53b27874c88e21f5d34b251 · apple/foundationdb · GitHub](https://github.com/apple/foundationdb/blob/c1acf5fc16a522b0f53b27874c88e21f5d34b251/build/Dockerfile#L79) , so it looks like your CVE scanner was correct and an openssl upgrade is needed.

It looks like the most recent 6.3.18 release was also compiled against 1.1.1h, so it too will need an update.

---

<div class="post-metadata">

**Author:** ![tuk](https://avatars.discourse-cdn.com/v4/letter/t/b5ac83/32.png) [@tuk](https://forums.foundationdb.org/u/tuk)\
**Post date:** [August 14, 2021, 6:39am UTC](https://forums.foundationdb.org/t/cve-2021-3450-in-foundationdb-6-2-30/2847/3 "2021-08-14T06:39:31Z")

</div>

Thanks, @alexmiller for the confirmation.

I could not find any open issue in [Github](https://github.com/apple/foundationdb/issues?q=is%3Aissue+is%3Aopen+openssl) to upgrade OpenSSL. So opened [Upgrade openssl to 1.1.1k for CVE-2021-3450 · Issue #5386 · apple/foundationdb · GitHub](https://github.com/apple/foundationdb/issues/5386).
