CVE-2022-1292

Command Injection
Affects
Node.js
in
Node.js
No items found.
Versions
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.15.1 >=17.0.0 <17.9.1 >=18.0.0 <18.2.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js does not rely on a system cryptography library by default: it carries a full copy of the OpenSSL source tree at deps/openssl and compiles the library from it, and software composition scanners identify that bundled copy by its OpenSSL version.

A vulnerability (CVE-2022-1292) has been identified in the c_rehash script that ships with OpenSSL, including the copy bundled in the Node.js source tree. c_rehash is a Perl helper that scans a directory of certificates and creates the hash-named links OpenSSL uses to look them up. It does not properly sanitize shell metacharacters in the file names it processes, so a certificate file with a crafted name can inject commands that run with the privileges of whoever, or whatever, runs the script.

This flaw maps to CWE-78 (Improper Neutralization of Special Elements used in an OS Command, 'OS Command Injection'), where software builds a shell command from outside input without neutralizing characters the shell treats as special. In c_rehash, certificate file names were placed into a shell command without being fully escaped. Some operating systems run c_rehash automatically, for example when certificates are added, which can turn the flaw into arbitrary command execution, often as root.

An attacker needs to place a certificate file with a malicious name in a directory that c_rehash later processes. The Node.js project assessed that Node.js does not use or ship the c_rehash script and is therefore not affected at runtime: the script is present only as the unbuilt template deps/openssl/openssl/tools/c_rehash.in in the source tree, and it is not part of the nodejs.org binary distributions. The listed versions are the Node.js releases whose bundled OpenSSL source predates the fix, which is what dependency scanners report against.

‍

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL source, including tools/c_rehash.in, under deps/openssl)
  • Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.15.1 >=17.0.0 <17.9.1 >=18.0.0 <18.2.0
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 14.19.3 and 18.2.0 (May 17, 2022) and 16.15.1 and 17.9.1 (June 1, 2022), regular releases that upgraded the bundled OpenSSL to 1.1.1o or 3.0.3; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same OpenSSL fix. The other release lines listed above never received an updated OpenSSL

Vulnerability Info

This vulnerability is found in the c_rehash script of OpenSSL 1.0.2 through 1.0.2zd, 1.1.1 through 1.1.1n, and 3.0.0 through 3.0.2, all of which Node.js has bundled. NVD assigns a CVSS v3.1 score of 7.3 (High) for a local attack that needs low privileges and user interaction; the CISA-ADP score in the CVE record is 9.8 (Critical), scoring it as a network attack with no privileges or interaction. OpenSSL rates the issue Moderate.

c_rehash is supposed to read the certificate files in a directory and create links named after each certificate's hash. In the vulnerable versions, it ran the openssl command through the shell with each certificate file name pasted into the command line, escaping only quote characters, so a name containing other shell metacharacters ran extra commands. The fix makes c_rehash invoke openssl directly instead of through a shell (except on VMS, where the shell form is safe), so file names are never interpreted by the shell. See the OpenSSL 1.1.1 fix commit for the exact change.

The impact is greatest where an operating system or tooling runs c_rehash automatically on a directory that less-trusted users or processes can write certificate files into. For Node.js specifically, the Node.js project's assessment is that the script is neither shipped nor used, so a Node.js process is not exposed through its runtime; the residual exposure is limited to anyone who builds or copies OpenSSL tooling out of a vulnerable Node.js source tree and then runs c_rehash.

Note: OpenSSL considers c_rehash obsolete and recommends the openssl rehash command instead, which is not affected by this issue.

‍

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

‍

Credits

  • Elison Niven from Sophos (reporter)
  • Tomáš Mráz from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2022-1292
PROJECT Affected
Node.js
Versions Affected
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.19.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.15.1 >=17.0.0 <17.9.1 >=18.0.0 <18.2.0
NES Versions Affected
Published date
October 1, 2026
≈ Fix date
July 30, 2024
Category
Command Injection
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.