First published: Thu Jul 14 2022(Updated: )
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nodejs Node.js | >=18.0.0<18.5.0 | |
Siemens Sinec Ins | <1.0 | |
Siemens Sinec Ins | =1.0 | |
Siemens Sinec Ins | =1.0-sp1 | |
Siemens Sinec Ins | =1.0-sp2 | |
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32222 is a cryptographic vulnerability in Node.js on Linux in versions of 18.x prior to 18.40.0.
The severity of CVE-2022-32222 is medium with a CVSS score of 5.3.
Node.js versions 18.x prior to 18.40.0 on Linux are affected by CVE-2022-32222.
The reference for CVE-2022-32222 is https://hackerone.com/reports/1695596.
The CWE of CVE-2022-32222 is CWE-427 and CWE-310.