Security features bypass in Node.js - CVE-2022-32222

 

Security features bypass in Node.js - CVE-2022-32222

Published: July 13, 2022 / Updated: October 4, 2022


Vulnerability identifier: #VU65280
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32222
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions

The vulnerability exists due to Node.js after start on linux based systems attempts to read /home/iojs/build/ws/out/Release/obj.target/deps/openssl/openssl.cnf, which ordinarily doesn't exist. A remote unauthenticated attacker can attemp to read openssl.cnf from /home/iojs/build/ upon startup to create this file and affect the default OpenSSL configuration for other users.


Affected software

Node.js
Gentoo Linux
Amazon Linux AMI
Answer Retrieval for Watson Discovery On Prem
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
IBM Planning Analytics Workspace
Cognos Dashboards on Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Cloud Pak for Multicloud Management Monitoring
IBM Spectrum Protect Plus
Event Streams
IBM Cognos Controller
SINEC INS
nodejs

How to mitigate CVE-2022-32222

Install updates from vendor's website.

Node.js - update to 18.9.1
Answer Retrieval for Watson Discovery On Prem - update to 2.8.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.0
Event Streams - update to 11.0.4
IBM Cognos Controller - update to 11.0.1.0.3
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-9, 2022.2-1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-8, 2022.2.1-1
SINEC INS - update to 1.0 SP2 Update 1
IBM Planning Analytics Workspace - update to 2.0.82
IBM Cloud Pak for Multicloud Management Monitoring - update to 2.3 Fix Pack 7
Cognos Dashboards on Cloud Pak for Data - update to 4.7.2
IBM Spectrum Protect Plus - update to 10.1.12
nodejs - update to 18.12.1-1

External References

Related Security Bulletins