OpenSSL 3.0.7 update assessment

Summary

The vulnerability in the OpenSSL Security Advisory of Dec 13 2022 do not affect any active Node.js release lines.

Analysis

Our assessment of the security advisory is:

X.509 Policy Constraints Double Locking (CVE-2022-3996)

Node.js doesn’t call OpenSSL as a separate process (so the possibility to use the -policy flag is invalid), nor call
the functions X509_VERIFY_PARAM_add0_policy()' and X509_VERIFY_PARAM_set1_policies()’.
Therefore, Node.js is not affected by this vulnerability.

Contact and future updates

The current Node.js security policy can be found at https://github.com/nodejs/node/blob/HEAD/SECURITY.md#security,
including information on how to report a vulnerability in Node.js.

Subscribe to the low-volume announcement-only nodejs-sec mailing list at
https://groups.google.com/forum/#!forum/nodejs-sec to stay up to date on
security vulnerabilities and security-related releases of Node.js and the
projects maintained in the
nodejs GitHub organization.


This content originally appeared on Node.js Blog and was authored by Rafael Gonzaga

Summary

The vulnerability in the OpenSSL Security Advisory of Dec 13 2022 do not affect any active Node.js release lines.

Analysis

Our assessment of the security advisory is:

X.509 Policy Constraints Double Locking (CVE-2022-3996)

Node.js doesn't call OpenSSL as a separate process (so the possibility to use the -policy flag is invalid), nor call the functions X509_VERIFY_PARAM_add0_policy()' and X509_VERIFY_PARAM_set1_policies()'. Therefore, Node.js is not affected by this vulnerability.

Contact and future updates

The current Node.js security policy can be found at https://github.com/nodejs/node/blob/HEAD/SECURITY.md#security, including information on how to report a vulnerability in Node.js.

Subscribe to the low-volume announcement-only nodejs-sec mailing list at https://groups.google.com/forum/#!forum/nodejs-sec to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization.


This content originally appeared on Node.js Blog and was authored by Rafael Gonzaga


Print Share Comment Cite Upload Translate Updates
APA

Rafael Gonzaga | Sciencx (2022-12-16T17:00:15+00:00) OpenSSL 3.0.7 update assessment. Retrieved from https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/

MLA
" » OpenSSL 3.0.7 update assessment." Rafael Gonzaga | Sciencx - Friday December 16, 2022, https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/
HARVARD
Rafael Gonzaga | Sciencx Friday December 16, 2022 » OpenSSL 3.0.7 update assessment., viewed ,<https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/>
VANCOUVER
Rafael Gonzaga | Sciencx - » OpenSSL 3.0.7 update assessment. [Internet]. [Accessed ]. Available from: https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/
CHICAGO
" » OpenSSL 3.0.7 update assessment." Rafael Gonzaga | Sciencx - Accessed . https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/
IEEE
" » OpenSSL 3.0.7 update assessment." Rafael Gonzaga | Sciencx [Online]. Available: https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/. [Accessed: ]
rf:citation
» OpenSSL 3.0.7 update assessment | Rafael Gonzaga | Sciencx | https://www.scien.cx/2022/12/16/openssl-3-0-7-update-assessment/ |

Please log in to upload a file.




There are no updates yet.
Click the Upload button above to add an update.

You must be logged in to translate posts. Please log in or register.