The c_rehash script allows command injection
Published Jun 21, 2022
9.8
CRITICALCVSS 3.1
EPSS 95.40%
Description
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
Affected products
-
- Version Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze)StatusaffectedConstraints-
- Version Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o)StatusaffectedConstraints-
- Version Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3)StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 10.0
- 11.0
Configuration 3
- 35
- 36
Configuration 4
Configuration 5
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 6
- n/a
Running on/with
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- n/a
Configuration 20
- n/a
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-openssl-1:1.1.1k-13.el8jbcs
Fixed · RHSA-2022:8840
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.1.1k-13.el7jbcs
Fixed · RHSA-2022:8840
JWS 5.7.1 release
openssl
Fixed · RHSA-2022:8913
Red Hat Enterprise Linux 8
openssl-1:1.1.1k-7.el8_6
Fixed · RHSA-2022:5818
Red Hat Enterprise Linux 9
openssl-1:3.0.1-41.el9_0
Fixed · RHSA-2022:6224
Red Hat Enterprise Linux 9
openssl-1:3.0.1-41.el9_0
Fixed · RHSA-2022:6224
Red Hat JBoss Web Server 5.7 on RHEL 7
jws5-tomcat-native-0:1.2.31-11.redhat_11.el7jws
Fixed · RHSA-2022:8917
Red Hat JBoss Web Server 5.7 on RHEL 8
jws5-tomcat-native-0:1.2.31-11.redhat_11.el8jws
Fixed · RHSA-2022:8917
Red Hat JBoss Web Server 5.7 on RHEL 9
jws5-tomcat-native-0:1.2.31-11.redhat_11.el9jws
Fixed · RHSA-2022:8917
Red Hat Satellite 6.11 for RHEL 7
puppet-agent-0:7.26.0-3.el7sat
Fixed · RHSA-2023:5980
Red Hat Satellite 6.11 for RHEL 7
puppet-agent-0:7.26.0-3.el7sat
Fixed · RHSA-2023:5980
Red Hat Satellite 6.11 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5980
Red Hat Satellite 6.11 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5980
Red Hat Satellite 6.12 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5979
Red Hat Satellite 6.12 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5979
Red Hat Satellite 6.13 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5931
Red Hat Satellite 6.13 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5931
Red Hat Satellite 6.14 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:6818
Red Hat Satellite 6.14 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:6818
Satellite Client 6 for RHEL 6
puppet-agent-0:7.26.0-3.el6sat
Fixed · RHSA-2023:5982
Satellite Client 6 for RHEL 7
puppet-agent-0:7.26.0-3.el7sat
Fixed · RHSA-2023:5982
Satellite Client 6 for RHEL 8
puppet-agent-0:7.26.0-3.el8sat
Fixed · RHSA-2023:5982
Satellite Client 6 for RHEL 9
puppet-agent-0:7.26.0-3.el9sat
Fixed · RHSA-2023:5982
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/management-ingress-rhel8
Will not fix
Red Hat Enterprise Linux 6
openssl
Out of support scope
Red Hat Enterprise Linux 6
openssl098e
Out of support scope
Red Hat Enterprise Linux 7
openssl
Out of support scope
Red Hat Enterprise Linux 7
openssl098e
Out of support scope
Red Hat Enterprise Linux 7
ovmf
Out of support scope
Red Hat Enterprise Linux 8
compat-openssl10
Out of support scope
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 9
compat-openssl11
Out of support scope
Red Hat Enterprise Linux 9
edk2
Not affected
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat JBoss Enterprise Application Platform 6
openssl
Out of support scope
Red Hat JBoss Web Server 3
openssl
Out of support scope
Red Hat Virtualization 4
redhat-virtualization-host
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-openssl-1:1.1.1k-13.el8jbcs | Fixed | RHSA-2022:8840 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.1.1k-13.el7jbcs | Fixed | RHSA-2022:8840 |
| JWS 5.7.1 release | openssl | Fixed | RHSA-2022:8913 |
| Red Hat Enterprise Linux 8 | openssl-1:1.1.1k-7.el8_6 | Fixed | RHSA-2022:5818 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-41.el9_0 | Fixed | RHSA-2022:6224 |
| Red Hat Enterprise Linux 9 | openssl-1:3.0.1-41.el9_0 | Fixed | RHSA-2022:6224 |
| Red Hat JBoss Web Server 5.7 on RHEL 7 | jws5-tomcat-native-0:1.2.31-11.redhat_11.el7jws | Fixed | RHSA-2022:8917 |
| Red Hat JBoss Web Server 5.7 on RHEL 8 | jws5-tomcat-native-0:1.2.31-11.redhat_11.el8jws | Fixed | RHSA-2022:8917 |
| Red Hat JBoss Web Server 5.7 on RHEL 9 | jws5-tomcat-native-0:1.2.31-11.redhat_11.el9jws | Fixed | RHSA-2022:8917 |
| Red Hat Satellite 6.11 for RHEL 7 | puppet-agent-0:7.26.0-3.el7sat | Fixed | RHSA-2023:5980 |
| Red Hat Satellite 6.11 for RHEL 7 | puppet-agent-0:7.26.0-3.el7sat | Fixed | RHSA-2023:5980 |
| Red Hat Satellite 6.11 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5980 |
| Red Hat Satellite 6.11 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5980 |
| Red Hat Satellite 6.12 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5979 |
| Red Hat Satellite 6.12 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5979 |
| Red Hat Satellite 6.13 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5931 |
| Red Hat Satellite 6.13 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5931 |
| Red Hat Satellite 6.14 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:6818 |
| Red Hat Satellite 6.14 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:6818 |
| Satellite Client 6 for RHEL 6 | puppet-agent-0:7.26.0-3.el6sat | Fixed | RHSA-2023:5982 |
| Satellite Client 6 for RHEL 7 | puppet-agent-0:7.26.0-3.el7sat | Fixed | RHSA-2023:5982 |
| Satellite Client 6 for RHEL 8 | puppet-agent-0:7.26.0-3.el8sat | Fixed | RHSA-2023:5982 |
| Satellite Client 6 for RHEL 9 | puppet-agent-0:7.26.0-3.el9sat | Fixed | RHSA-2023:5982 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/management-ingress-rhel8 | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssl098e | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssl098e | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | openssl | Out of support scope | n/a |
| Red Hat JBoss Web Server 3 | openssl | Out of support scope | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux uses a system-wide store of trusted certificates bundled in a single file and updated via `update-ca-trust`. The `c_rehash` script is not included in the default installation on any supported RHEL version and is never executed automatically. For these reasons, this flaw has been rated as having a security impact of Moderate. Red Hat Enterprise Linux 7 provides a vulnerable version of the `c_rehash` script in the `openssl-perl` package, available only through the unsupported Optional repository. As the Optional repository is not supported and Red Hat Enterprise Linux 7 is in Maintenance Support 2 Phase, this issue is not planned to be addressed there. Red Hat Satellite ships an affected version of the `c_rehash` script embedded in `puppet-agent` package, however, the product is not vulnerable since it does not execute scripts with untrusted data. Moreover, the scriplet is owned by root user and is supposed to be accessed only by administrators. Red Hat updates the OpenSSL compatibility packages (compat-openssl) to only address Important or Critical security issues with backported security patches.
Red Hat mitigation
As mentioned in the upstream security advisory, use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command-line tool.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
2 other sources (CISA ADP, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Apr 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (77 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 95.40% (0.95404) | 99.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 95.76% (0.95764) | 99.86th | v5 (v2026.06.15) |
| May 13, 2026 | 20.22% (0.20216) | 95.56th | v4 (v2025.03.14) |
| Mar 4, 2026 | 18.58% (0.18580) | 95.13th | v4 (v2025.03.14) |
| Mar 1, 2026 | 6.65% (0.06646) | 91.07th | v4 (v2025.03.14) |
| Feb 14, 2026 | 20.22% (0.20216) | 95.35th | v4 (v2025.03.14) |
| Feb 4, 2026 | 18.58% (0.18580) | 95.07th | v4 (v2025.03.14) |
| Feb 1, 2026 | 6.00% (0.06003) | 90.50th | v4 (v2025.03.14) |
| Jan 5, 2026 | 18.58% (0.18580) | 95.03th | v4 (v2025.03.14) |
| Jan 4, 2026 | 23.33% (0.23333) | 95.77th | v4 (v2025.03.14) |
| Jan 1, 2026 | 6.00% (0.06003) | 90.45th | v4 (v2025.03.14) |
| Dec 28, 2025 | 23.33% (0.23333) | 95.77th | v4 (v2025.03.14) |
| Dec 27, 2025 | 21.86% (0.21857) | 95.59th | v4 (v2025.03.14) |
| Dec 23, 2025 | 23.33% (0.23333) | 95.77th | v4 (v2025.03.14) |
| Dec 22, 2025 | 21.05% (0.21053) | 95.46th | v4 (v2025.03.14) |
| Dec 4, 2025 | 23.33% (0.23333) | 95.73th | v4 (v2025.03.14) |
| Dec 1, 2025 | 6.00% (0.06003) | 90.37th | v4 (v2025.03.14) |
| Nov 27, 2025 | 23.33% (0.23333) | 95.74th | v4 (v2025.03.14) |
| Nov 21, 2025 | 25.23% (0.25231) | 95.97th | v4 (v2025.03.14) |
| Nov 18, 2025 | 19.00% (0.19005) | 94.88th | v4 (v2025.03.14) |
| Nov 4, 2025 | 25.23% (0.25231) | 95.95th | v4 (v2025.03.14) |
| Nov 1, 2025 | 6.65% (0.06646) | 90.83th | v4 (v2025.03.14) |
| Oct 28, 2025 | 25.23% (0.25231) | 95.93th | v4 (v2025.03.14) |
| Oct 27, 2025 | 23.68% (0.23680) | 95.75th | v4 (v2025.03.14) |
| Oct 4, 2025 | 25.23% (0.25231) | 95.99th | v4 (v2025.03.14) |
| Oct 1, 2025 | 6.65% (0.06646) | 90.88th | v4 (v2025.03.14) |
| Sep 26, 2025 | 21.86% (0.21857) | 95.58th | v4 (v2025.03.14) |
| Sep 24, 2025 | 23.68% (0.23680) | 95.80th | v4 (v2025.03.14) |
| Sep 5, 2025 | 21.86% (0.21857) | 95.55th | v4 (v2025.03.14) |
| Sep 4, 2025 | 66.73% (0.66729) | 98.49th | v4 (v2025.03.14) |
| Sep 1, 2025 | 51.85% (0.51848) | 97.84th | v4 (v2025.03.14) |
| Aug 31, 2025 | 66.73% (0.66729) | 98.48th | v4 (v2025.03.14) |
| Aug 27, 2025 | 69.30% (0.69299) | 98.58th | v4 (v2025.03.14) |
| Aug 25, 2025 | 51.85% (0.51848) | 97.81th | v4 (v2025.03.14) |
| Aug 4, 2025 | 69.30% (0.69299) | 98.57th | v4 (v2025.03.14) |
| Aug 1, 2025 | 51.85% (0.51848) | 97.82th | v4 (v2025.03.14) |
| Jul 30, 2025 | 69.30% (0.69299) | 98.57th | v4 (v2025.03.14) |
| Jul 4, 2025 | 71.23% (0.71230) | 98.62th | v4 (v2025.03.14) |
| Jul 1, 2025 | 54.68% (0.54682) | 97.90th | v4 (v2025.03.14) |
| Jun 25, 2025 | 71.23% (0.71230) | 98.61th | v4 (v2025.03.14) |
| Jun 23, 2025 | 73.98% (0.73985) | 98.74th | v4 (v2025.03.14) |
| Jun 22, 2025 | 72.16% (0.72161) | 98.66th | v4 (v2025.03.14) |
| Jun 5, 2025 | 71.04% (0.71041) | 98.60th | v4 (v2025.03.14) |
| Jun 4, 2025 | 72.65% (0.72645) | 98.68th | v4 (v2025.03.14) |
| Jun 1, 2025 | 56.67% (0.56674) | 97.98th | v4 (v2025.03.14) |
| May 6, 2025 | 72.65% (0.72645) | 98.67th | v4 (v2025.03.14) |
| May 4, 2025 | 71.04% (0.71041) | 98.60th | v4 (v2025.03.14) |
| May 1, 2025 | 54.42% (0.54421) | 97.86th | v4 (v2025.03.14) |
| Mar 30, 2025 | 71.04% (0.71041) | 98.61th | v4 (v2025.03.14) |
| Mar 29, 2025 | 83.39% (0.83392) | 99.09th | v4 (v2025.03.14) |
| Mar 17, 2025 | 71.04% (0.71041) | 98.61th | v4 (v2025.03.14) |
| Mar 6, 2025 | 15.05% (0.15047) | 95.93th | v3 (v2023.03.01) |
| Jan 25, 2025 | 13.88% (0.13881) | 95.67th | v3 (v2023.03.01) |
| Dec 30, 2024 | 12.69% (0.12694) | 95.45th | v3 (v2023.03.01) |
| Dec 17, 2024 | 16.02% (0.16017) | 95.94th | v3 (v2023.03.01) |
| Sep 12, 2024 | 12.26% (0.12263) | 95.52th | v3 (v2023.03.01) |
| Jun 5, 2024 | 9.32% (0.09320) | 94.56th | v3 (v2023.03.01) |
| Feb 10, 2024 | 8.51% (0.08509) | 94.23th | v3 (v2023.03.01) |
| Jan 27, 2024 | 9.05% (0.09050) | 94.05th | v3 (v2023.03.01) |
| Jan 12, 2024 | 13.26% (0.13258) | 95.04th | v3 (v2023.03.01) |
| Dec 2, 2023 | 12.73% (0.12731) | 94.89th | v3 (v2023.03.01) |
| Nov 19, 2023 | 11.11% (0.11112) | 94.59th | v3 (v2023.03.01) |
| Nov 8, 2023 | 10.52% (0.10516) | 94.43th | v3 (v2023.03.01) |
| Oct 23, 2023 | 13.26% (0.13261) | 94.92th | v3 (v2023.03.01) |
| Sep 26, 2023 | 11.02% (0.11015) | 94.45th | v3 (v2023.03.01) |
| Jul 24, 2023 | 13.77% (0.13766) | 94.89th | v3 (v2023.03.01) |
| Jul 8, 2023 | 13.72% (0.13722) | 94.88th | v3 (v2023.03.01) |
| Jun 28, 2023 | 18.03% (0.18029) | 95.43th | v3 (v2023.03.01) |
| May 22, 2023 | 25.15% (0.25153) | 95.97th | v3 (v2023.03.01) |
| May 8, 2023 | 25.30% (0.25304) | 95.95th | v3 (v2023.03.01) |
| Mar 7, 2023 | 26.57% (0.26569) | 95.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.54% (0.03535) | 84.88th | v2 (v2022.01.01) |
| Jan 11, 2023 | 3.54% (0.03535) | 84.35th | v2 (v2022.01.01) |
| Jul 23, 2022 | 2.73% (0.02734) | 81.94th | v2 (v2022.01.01) |
| Jul 6, 2022 | 2.56% (0.02564) | 80.78th | v2 (v2022.01.01) |
| Jun 30, 2022 | 2.36% (0.02359) | 80.24th | v2 (v2022.01.01) |
| Jun 22, 2022 | 1.08% (0.01079) | 50.11th | v2 (v2022.01.01) |
References (15)
- http://seclists.org/fulldisclosure/2024/Nov/0
- https://access.redhat.com/security/cve/CVE-2022-2068 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2097310 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf Third Party Advisory
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfa Patch
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9 Patch
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7 Patch
- https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/ vendor-advisoryMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2068
- https://security.netapp.com/advisory/ntap-20220707-0008/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2068
- https://www.debian.org/security/2022/dsa-5169 vendor-advisoryThird Party Advisory
- https://www.openssl.org/news/secadv/20220621.txt Vendor Advisory
Change history (3)
- CISA ADP
- SSVC exploitation changed from poc to
none poc → none
- SSVC exploitation changed from poc to
none
- CISA ADP
- SSVC exploitation changed from none to
poc none → poc
- SSVC exploitation changed from none to
poc
- CISA ADP
- SSVC exploitation changed from poc to
none poc → none
- SSVC exploitation changed from poc to
none