CVE-2022-2068
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js does not rely on a system cryptography library by default: it carries a full copy of the OpenSSL source tree at deps/openssl and compiles the library from it, and software composition scanners identify that bundled copy by its OpenSSL version.
A vulnerability (CVE-2022-2068) has been identified in the c_rehash script that ships with OpenSSL, including the copy bundled in the Node.js source tree. c_rehash is a Perl helper that creates the hash-named links OpenSSL uses to look up certificates in a directory. After the command injection fixed as CVE-2022-1292, a code review found further places where the script passed certificate file names to commands run through the shell, so a file with a crafted name could still inject commands that run with the privileges of whoever, or whatever, runs the script.
This flaw maps to CWE-78 (Improper Neutralization of Special Elements used in an OS Command, 'OS Command Injection'), where software builds a shell command from outside input without neutralizing characters the shell treats as special. In c_rehash, the commands that copy, link and remove certificate files still embedded the file names in shell command lines. Some operating systems run c_rehash automatically, for example when certificates are added, which can turn the flaw into arbitrary command execution, often as root.
An attacker needs to place a certificate file with a malicious name in a directory that c_rehash later processes. The Node.js project assessed that Node.js does not use or ship the c_rehash script and is therefore not affected at runtime: the script is present only as the unbuilt template deps/openssl/openssl/tools/c_rehash.in in the source tree, and it is not part of the nodejs.org binary distributions. The listed versions are the Node.js releases whose bundled OpenSSL source predates the fix, which is what dependency scanners report against.
Details
Module Info
- Product: Node.js
- Affected packages: node (bundles OpenSSL source, including
tools/c_rehash.in, underdeps/openssl) - Affected versions: >=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.20.0 >=15.0.0 <=15.14.0 >=16.0.0 <16.16.0 >=17.0.0 <=17.9.1 >=18.0.0 <18.5.0
- GitHub repository: https://github.com/nodejs/node
- Published packages: https://nodejs.org/en/download
- Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
- Fixed in: Node.js 14.20.0, 16.16.0 and 18.5.0 (all July 7, 2022), which upgraded the bundled OpenSSL to 1.1.1q or 3.0.5; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), a later cumulative build carrying the same OpenSSL fix. The other release lines listed above never received an updated OpenSSL
Vulnerability Info
This vulnerability is found in the c_rehash script of OpenSSL 1.0.2 through 1.0.2ze, 1.1.1 through 1.1.1o, and 3.0.0 through 3.0.3, all of which Node.js has bundled. NVD assigns a CVSS v3.1 score of 7.3 (High) for a local attack that needs low privileges and user interaction; the CISA-ADP score in the CVE record is 9.8 (Critical). OpenSSL rates the issue Moderate.
c_rehash is supposed to read the certificate files in a directory and create links named after each certificate's hash, copying or removing files as needed. The CVE-2022-1292 fix stopped the script from passing file names to the shell when it ran openssl, but the routines that copy, link and remove files still built shell commands containing those names. The fix replaces those shell commands with Perl's own file operations, so file names are never interpreted by the shell. See the OpenSSL 1.1.1 fix commit for the exact change.
The impact is greatest where an operating system or tooling runs c_rehash automatically on a directory that less-trusted users or processes can write certificate files into. For Node.js specifically, the Node.js project's assessment is that the script is neither shipped nor used, so a Node.js process is not exposed through its runtime; the residual exposure is limited to anyone who builds or copies OpenSSL tooling out of a vulnerable Node.js source tree and then runs c_rehash.
Note: OpenSSL considers c_rehash obsolete and recommends the openssl rehash command instead, which is not affected by this issue.
Mitigation
Users of the affected components should apply one of the following mitigations:
- Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
- Migrate affected applications away from the End-of-Life Node.js release lines.
- Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.
Credits
- Chancen from Qingteng 73lab (reporter)
- Daniel Fiala from the OpenSSL project (finder of a further instance; remediation developer)
- Tomáš Mráz from the OpenSSL project (remediation developer)