CVE-2022-32222

CVSS V2 None CVSS V3 Medium 5.3
Description
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.
Overview
  • CVE ID
  • CVE-2022-32222
  • Assigner
  • support@hackerone.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2022-07-14T15:15:08
  • Last Modified Date
  • 2023-02-23T20:15:12
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* 1 OR 18.0.0 18.5.0
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • NONE
  • Availability Impact
  • NONE
  • Base Score
  • 5.3
  • Base Severity
  • MEDIUM
  • Exploitability Score
  • 3.9
  • Impact Score
  • 1.4
History
Created Old Value New Value Data Type Notes
2022-07-14 16:00:10 Added to TrackCVE
2023-01-10 13:17:19 2023-01-10T13:15:15 CVE Modified Date updated
2023-01-10 13:17:19 Analyzed Modified Vulnerability Status updated
2023-01-10 13:17:20 Weakness Enumeration update
2023-01-10 13:17:21 References updated
2023-01-12 05:14:33 Modified Undergoing Analysis Vulnerability Status updated
2023-01-23 17:12:50 2023-01-23T16:15:10 CVE Modified Date updated
2023-01-23 17:12:51 A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3. A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.4.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3. Description updated
2023-02-23 17:13:29 2023-02-23T16:44:05 CVE Modified Date updated
2023-02-23 17:13:29 Undergoing Analysis Analyzed Vulnerability Status updated
2023-02-23 21:14:14 2023-02-23T20:15:12 CVE Modified Date updated
2023-02-23 21:14:14 Analyzed Modified Vulnerability Status updated
2023-02-23 21:14:15 A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.4.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3. A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3. Description updated