Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32222

Опубликовано: 14 июл. 2022
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
Версия от 18.0.0 (включая) до 18.5.0 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*
Версия до 1.0 (исключая)
cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_ins:1.0:sp2:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.0042
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-310
CWE-427

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 3 года назад

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

CVSS3: 5.3
redhat
почти 3 года назад

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

CVSS3: 5.3
debian
почти 3 года назад

A cryptographic vulnerability exists on Node.js on linux in versions o ...

CVSS3: 5.3
github
почти 3 года назад

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

oracle-oval
больше 2 лет назад

ELSA-2022-9955: GraalVM Security update (IMPORTANT)

EPSS

Процентиль: 61%
0.0042
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-310
CWE-427