2022 November 9
Discourse has confirmed that current Discourse Docker images, as used
by SCANALYST, are not vulnerable to the OpenSSL vulnerabilities
recently discovered and widely reported.
https://meta.discourse.org/t/statement-regarding-openssl-vulnerabilities-2022-11-01/244230
https://www.openssl.org/news/secadv/20221101.txt
The vulnerability exists in OpenSSL versions between 3.0.0 and 3.0.6.
Discourse is bundled with Debian OpenSSL 1.1.1n-0+deb11u3, a
still-supported version which is not vulnerable.