OpenSSL update assessment, and Node.js project plans
source link: https://nodejs.org/en/blog/vulnerability/openssl-fixes-in-regular-releases-jun2022/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
OpenSSL update assessment, and Node.js project plans
by Rafael Gonzaga, 2022-06-21Summary
The vulnerabilities in the OpenSSL Security releases of Jun 21 2022 do not affect any active Node.js release lines.
Analysis
Our assessment of the security advisory is:
The c_rehash
script allows command injection (CVE-2022-2068)
Node.js doesn't use or ship the c_rehash
script. Therefore, Node.js is not affected
Contact and future updates
The current Node.js security policy can be found at https://github.com/nodejs/node/blob/HEAD/SECURITY.md#security, including information on how to report a vulnerability in Node.js.
Subscribe to the low-volume announcement-only nodejs-sec mailing list at https://groups.google.com/forum/#!forum/nodejs-sec to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization.
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK