CVE-2022-32222

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-32222
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32222.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-32222
Aliases
Published
2022-07-14T15:15:08Z
Modified
2024-06-06T14:04:02.382797Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

References

Affected packages

Git / github.com/nodejs/node

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/node
Events

Affected versions

v18.*

v18.0.0
v18.1.0
v18.2.0
v18.3.0
v18.4.0