Security notice from my Netgear Armor scan

heavygravity

New Member
May 15, 2023
1
0
1
Hey all!

Perhaps a bit of a beginner question here, especially on the security side. I got a notice for 2 vulnerabilities with open ssh version that is running on ProxMox. It is mentioning that OpenSSH_8.4p1 is vulnerable on CVE-2023-28531 and CVE-2008-3844.

Interestingly I think both of these are false positives because CVE-2023-28531 states versions 8.9 up to 9.3. and 2008-3844 mentions "some" packages for RHEL 4 and 5. Perhaps BitDefender's repo of vulnerabilities is incorrect here?

Screenshot 2023-05-15 at 12.55.50 PM.png

I would gladly take some input on this. Is there a good way to update to 9.3?

Note: I did not grab a weird ISO - the installer was straight from proxmox (non-torrent sites - direct iso).
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!