Back

MEDIUM

nodejs: potential openssl.cnf hijack

Published Jul 14, 2022

Description

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

Affected products

Remediation

Red Hat statement

This issue is specific to the nodejs:v18 stream. This issue is contained within the OpenSSL library bundled upstream. We remove this library during the build and instead, use the one on the system, therefore, this issue does not affect us.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner hackerone
Published Jul 14, 2022
Updated Apr 30, 2025
Reserved Jun 1, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 8, 2022
Bugzilla 2105424

ENISA EUVD

Assigner hackerone
Published Jul 14, 2022
Updated Apr 30, 2025

GitHub

No data