Lucene search

K
nodejsblogOpenJS FoundationNODEJSBLOG:VULNERABILITY
HistoryJun 21, 2022 - 12:00 a.m.

OpenSSL update assessment, and Node.js project plans

2022-06-2100:00:00
OpenJS Foundation
nodejs.org
598

8.2 High

AI Score

Confidence

Low

0.093 Low

EPSS

Percentile

94.7%

OpenSSL update assessment, and Node.js project plans

By Rafael Gonzaga, Jun 21, 2022

Summary

The vulnerabilities in the OpenSSL Security releases of Jun 21 2022 do not affect any active Node.js release lines.

Analysis

Our assessment of the security advisory is:

The c_rehash script allows command injection (CVE-2022-2068)

Node.js doesn’t use or ship the c_rehash script. Therefore, Node.js is not affected

Contact and future updates

The current Node.js security policy can be found at <https://github.com/nodejs/node/security/policy#security&gt;, including information on how to report a vulnerability in Node.js.

Subscribe to the low-volume announcement-only nodejs-sec mailing list at <https://groups.google.com/forum/#!forum/nodejs-sec&gt; to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization.