Lucene search

K
nodejsblogOpenJS FoundationNODEJSBLOG:OPENSSL-FIXES-IN-REGULAR-RELEASES-DEC2022
HistoryDec 16, 2022 - 12:00 a.m.

OpenSSL 3.0.7 update assessment

2022-12-1600:00:00
OpenJS Foundation
nodejs.org
13
openssl
vulnerability
x.509 policy constraints
node.js
security policy
security advisory
cve-2022-3996
github organization
security.md
mailing list
security-related releases

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.2%

Summary

The vulnerability in the OpenSSL Security Advisory of Dec 13 2022 do not affect any active Node.js release lines.

Analysis

Our assessment of the security advisory is:

X.509 Policy Constraints Double Locking (CVE-2022-3996)

Node.js doesn’t call OpenSSL as a separate process (so the possibility to use the -policy flag is invalid), nor call the functions X509_VERIFY_PARAM_add0_policy() and X509_VERIFY_PARAM_set1_policies(). Therefore, Node.js is not affected by this vulnerability.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.2%