Bug 2105424 (CVE-2022-32222) - CVE-2022-32222 nodejs: potential openssl.cnf hijack
Summary: CVE-2022-32222 nodejs: potential openssl.cnf hijack
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2022-32222
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2108469 2108480
Blocks: 2105423
TreeView+ depends on / blocked
 
Reported: 2022-07-08 18:44 UTC by Sage McTaggart
Modified: 2022-08-31 16:25 UTC (History)
11 users (show)

Fixed In Version: nodejs 18.5.0
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in NodeJS. The issue occurs when Node.js starts on Linux based systems and attempts to read /home/iojs/build/ws/out/Release/obj.target/deps/openssl/openssl.cnf, which ordinarily does not exist. This flaw allows an attacker on some shared systems to create this file and affect the default OpenSSL configuration for other users.
Clone Of:
Environment:
Last Closed: 2022-08-31 16:25:51 UTC
Embargoed:


Attachments (Terms of Use)

Description Sage McTaggart 2022-07-08 18:44:01 UTC
CVE-2022-32222

When Node.js starts on linux based systems, it attempts to read /home/iojs/build/ws/out/Release/obj.target/deps/openssl/openssl.cnf, which ordinarily doesn't exist. On some shared systems an attacker may be able create this file and therefore affect the default OpenSSL configuration for other users.

Thank you to Michael Scovetta from the OpenSSF Alpha-Omega project for reporting this vulnerability.

Impacts:

Node.js 18.x

Comment 2 TEJ RATHI 2022-07-19 07:45:09 UTC
Created nodejs:18/nodejs tracking bugs for this issue:

Affects: fedora-all [bug 2108480]

Comment 7 Product Security DevOps Team 2022-08-31 16:25:49 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-32222


Note You need to log in before you can comment on or make changes to this bug.