Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-32222

A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.9%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-32222
  • Nodejs » Node.js » Version: 18.0.0
    cpe:2.3:a:nodejs:node.js:18.0.0
  • Nodejs » Node.js » Version: 18.0.1
    cpe:2.3:a:nodejs:node.js:18.0.1
  • Nodejs » Node.js » Version: 18.0.2
    cpe:2.3:a:nodejs:node.js:18.0.2
  • Nodejs » Node.js » Version: 18.0.3
    cpe:2.3:a:nodejs:node.js:18.0.3
  • Nodejs » Node.js » Version: 18.0.4
    cpe:2.3:a:nodejs:node.js:18.0.4
  • Nodejs » Node.js » Version: 18.0.5
    cpe:2.3:a:nodejs:node.js:18.0.5
  • Nodejs » Node.js » Version: 18.0.6
    cpe:2.3:a:nodejs:node.js:18.0.6
  • Nodejs » Node.js » Version: 18.1.0
    cpe:2.3:a:nodejs:node.js:18.1.0
  • Nodejs » Node.js » Version: 18.2.0
    cpe:2.3:a:nodejs:node.js:18.2.0
  • Nodejs » Node.js » Version: 18.3.0
    cpe:2.3:a:nodejs:node.js:18.3.0
  • Nodejs » Node.js » Version: 18.4.0
    cpe:2.3:a:nodejs:node.js:18.4.0
  • Siemens » Sinec Ins » Version: N/A
    cpe:2.3:a:siemens:sinec_ins:-
  • Siemens » Sinec Ins » Version: 1.0
    cpe:2.3:a:siemens:sinec_ins:1.0


Contact Us

Shodan ® - All rights reserved