nodejs: weak randomness in WebCrypto keygen
Published Dec 5, 2022
9.1
CRITICALCVSS 3.1
EPSS 2.09%
Description
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.
Affected products
-
Affected
- ≥ 10.0, < 10.*
- ≥ 11.0, < 11.*
- ≥ 12.0, < 12.*
- ≥ 13.0, < 13.*
- ≥ 15.0, < 15.*
- ≥ 17.0, < 17.*
- ≥ 18.0, < 18.9.1
- ≥ 4.0, < 4.*
- ≥ 5.0, < 5.*
- ≥ 6.0, < 6.*
- ≥ 7.0, < 7.*
- ≥ 8.0, < 8.*
- ≥ 9.0, < 9.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
Configuration 1
Configuration 2
Configuration 3
- 11.0
No data.
Red Hat Enterprise Linux 8
nodejs:16-8060020221007164523.ad008a3a
Fixed · RHSA-2022:6964
Red Hat Enterprise Linux 8
nodejs:18-8070020221004121421.bd1311ed
Fixed · RHSA-2022:7821
Red Hat Enterprise Linux 9
nodejs-1:16.17.1-1.el9_0
Fixed · RHSA-2022:6963
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:18/nodejs
Not affected
Red Hat Software Collections
rh-nodejs14-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:16-8060020221007164523.ad008a3a | Fixed | RHSA-2022:6964 |
| Red Hat Enterprise Linux 8 | nodejs:18-8070020221004121421.bd1311ed | Fixed | RHSA-2022:7821 |
| Red Hat Enterprise Linux 9 | nodejs-1:16.17.1-1.el9_0 | Fixed | RHSA-2022:6963 |
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerability was introduced in NodeJS v15.0.0, Hence, NodeJS:14 package in RHEL-8 and RHSCL-3 are not affected.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-35255 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2130517 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf Third Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38146 Advisory
- https://hackerone.com/bugs?report_id=1690000
- https://hackerone.com/reports/1690000 ExploitIssue TrackingThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/september-2022-security-releases/#weak-randomness-in-webcrypto-keygen-high-cve-2022-35255
- https://nvd.nist.gov/vuln/detail/CVE-2022-35255
- https://security.netapp.com/advisory/ntap-20230113-0002/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-35255
- https://www.debian.org/security/2023/dsa-5326 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-35255 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2130517 | Issue Tracking | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf | Third Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38146 | Advisory | |
| https://hackerone.com/bugs?report_id=1690000 | ||
| https://hackerone.com/reports/1690000 | ExploitIssue TrackingThird Party Advisory | |
| https://nodejs.org/en/blog/vulnerability/september-2022-security-releases/#weak-randomness-in-webcrypto-keygen-high-cve-2022-35255 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-35255 | ||
| https://security.netapp.com/advisory/ntap-20230113-0002/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-35255 | ||
| https://www.debian.org/security/2023/dsa-5326 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data