nodejs: potential openssl.cnf hijack
Published Jul 14, 2022
5.3
MEDIUMCVSS 3.1
EPSS 2.19%
Description
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.
Affected products
-
Affected
- ≥ 10.0, < 10.*
- ≥ 11.0, < 11.*
- ≥ 12.0, < 12.*
- ≥ 13.0, < 13.*
- ≥ 14.0, < 14.20.0
- ≥ 15.0, < 15.*
- ≥ 16.0, < 16.20.0
- ≥ 17.0, < 17.*
- ≥ 18.0, < 18.9.1
- ≥ 4.0, < 4.*
- ≥ 5.0, < 5.*
- ≥ 6.0, < 6.*
- ≥ 7.0, < 7.*
- ≥ 8.0, < 8.*
- ≥ 9.0, < 9.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:16/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:18/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs
Not affected
Red Hat Software Collections
rh-nodejs14-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:16/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue is specific to the nodejs:v18 stream. This issue is contained within the OpenSSL library bundled upstream. We remove this library during the build and instead, use the one on the system, therefore, this issue does not affect us.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-32222 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2105424 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53423 Advisory
- https://hackerone.com/reports/1695596 Exploit
- https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/
- https://nvd.nist.gov/vuln/detail/CVE-2022-32222
- https://www.cve.org/CVERecord?id=CVE-2022-32222
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data