The latest version of Box Drive for Windows (2.41.226) still contains outdated OpenSSL binaries (libcrypto-3 3.0.11 and libssl-3 3.0.11) which are vulnerable to several CVEs including CVE-2024-4741 (CVSS 8.1). Please patch these binaries as they are currently greatly elevating our enterprise vulnerability score across several security platforms.
Question
OpenSSL Vulnerabilities still in Latest Versions of Box Drive
Sign up
Already have an account? Login
Community access is available only with a Box Account.
Sign in with your Box AccountSign in to the Box Community
No account yet? Create an account
Community access is available only with a Box Account.
Sign in with your Box AccountEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.
