CVE-2023-2975

Cryptographic Weakness
Affects
Node.js
in
Node.js
No items found.
Versions
>=17.0.0 <=17.9.1 >=18.0.0 <18.17.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.1

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js compiles its own copy of OpenSSL from deps/openssl in the Node.js source tree and statically links it into the runtime, so a flaw in the bundled OpenSSL is present in every Node.js binary built from that tree. Node.js 17.x was the first release line to bundle OpenSSL 3.0.

A vulnerability (CVE-2023-2975) has been identified in the OpenSSL 3.0 library bundled with Node.js. OpenSSL's implementation of the AES-SIV cipher ignores empty associated data entries instead of authenticating them. An application that relies on AES-SIV to authenticate empty associated data entries can therefore be misled by an attacker who removes, adds or reorders such entries, because the result still passes the integrity check.

This flaw maps to CWE-354 (Improper Validation of Integrity Check Value), where software does not correctly validate the value meant to prove data has not been altered. AES-SIV is an authenticated encryption mode that can authenticate several separate pieces of associated data, each of which is bound into the authentication tag, including empty ones. In OpenSSL 3.0, a call meant to add an empty piece of associated data returned success without doing anything, so empty entries never contributed to the tag.

Exposure is narrow. Only applications that use AES-SIV and deliberately authenticate empty associated data entries are affected, and OpenSSL knew of no such applications. Non-empty associated data is authenticated correctly. Node.js's built-in crypto module does not offer AES-SIV, because OpenSSL 3.0 provides it only through its provider interface and Node.js looks ciphers up through the legacy name table, so exposure in a Node.js deployment depends on native addons or embedders that use AES-SIV through the bundled OpenSSL. This issue affects the Node.js 17.x, 18.x, 19.x and 20.x release lines up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles OpenSSL 3.0 under deps/openssl)
  • Affected versions: >=17.0.0 <=17.9.1 >=18.0.0 <18.17.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.1
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 18.17.1 and 20.5.1 (August 9, 2023), security releases that upgraded the bundled OpenSSL to 3.0.10; this CVE is also listed in the Node.js NES v16.20.3 release notes (16.x line, shipped July 30, 2024). Node.js 17.x and 19.x never received a fix

Vulnerability Info

This Medium-severity vulnerability is found in OpenSSL 3.0.0 through 3.0.9 (and 3.1.0 through 3.1.1), the versions bundled by Node.js 17.x through 20.x before the releases listed above. NVD assigns a CVSS v3.1 score of 5.3; OpenSSL rates the issue Low under its own severity policy.

With AES-SIV, an application authenticates a piece of associated data by calling EVP_EncryptUpdate() or EVP_CipherUpdate() with a NULL output buffer, and an empty piece by doing so with an input length of 0. In the vulnerable versions, the provider's update function returned success as soon as it saw a zero length, before checking whether the call was for associated data, so the empty entry was never fed into the authentication. The fix applies the zero-length shortcut only to real encryption or decryption calls and processes associated data calls, empty or not, as authentication input. See the OpenSSL 3.0 fix commit for the exact change.

An attacker able to modify AES-SIV-protected messages in transit or at rest could add, drop or reorder empty associated data entries without the receiver detecting it. Whether that matters depends entirely on what the application uses those empty entries to signal. The ciphertext and any non-empty associated data remain protected.

Note: OpenSSL 1.1.1 and 1.0.2 do not implement AES-SIV and are not affected, and OpenSSL's FIPS provider does not implement it either. Node.js release lines that bundle OpenSSL 1.1.1 or older, including 16.x and earlier, are not exposed by this issue, and neither are Node.js applications that use only the built-in crypto, tls and https modules.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle OpenSSL 3.5, which includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • Juerg Wullschleger from Google (reporter)
  • Tomáš Mráz from the OpenSSL project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Medium
ID
CVE-2023-2975
PROJECT Affected
Node.js
Versions Affected
>=17.0.0 <=17.9.1 >=18.0.0 <18.17.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.1
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Cryptographic Weakness
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.