nodejs node-js CVE-2022-32222 in nodejs and Siemens Products
Published on July 14, 2022

product logo product logo
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.

NVD

Weakness Type

Cryptographic Issues

Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.


Products Associated with CVE-2022-32222

stack.watch emails you whenever new vulnerabilities are published in nodejs node.js or Siemens Sinec Ins. Just hit a watch button to start following.

 
 

Affected Versions

NodeJS Node:

Exploit Probability

EPSS
0.62%
Percentile
69.71%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.