Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2022-35255 CVE-2022-35256 |
CWE-ID | CWE-330 CWE-444 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
nodejs (Red Hat package) Operating systems & Components / Operating system package or component Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions Operating systems & Components / Operating system package or component Red Hat Enterprise Linux for ARM 64 - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for ARM 64 Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, little endian - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, little endian Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems Operating systems & Components / Operating system Red Hat Enterprise Linux for x86_64 - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for x86_64 Operating systems & Components / Operating system |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU67849
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-35255
CWE-ID:
CWE-330 - Use of Insufficiently Random Values
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to decrypt sensitive information.
The vulnerability exists due to usage of weak randomness in WebCrypto keygen within the SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. A remote attacker can decrypt sensitive information.
Install updates from vendor's website.
nodejs (Red Hat package): 16.16.0-1.el9_0
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions: 9.0
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 9.0
Red Hat Enterprise Linux for ARM 64: 9
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 9.0
Red Hat Enterprise Linux for Power, little endian: 9
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 9.0
Red Hat Enterprise Linux for IBM z Systems: 9
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 9.0
Red Hat Enterprise Linux for x86_64: 9
CPE2.3https://access.redhat.com/errata/RHSA-2022:6963
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU67850
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-35256
CWE-ID:
CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
MitigationInstall updates from vendor's website.
nodejs (Red Hat package): 16.16.0-1.el9_0
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions: 9.0
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 9.0
Red Hat Enterprise Linux for ARM 64: 9
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 9.0
Red Hat Enterprise Linux for Power, little endian: 9
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 9.0
Red Hat Enterprise Linux for IBM z Systems: 9
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 9.0
Red Hat Enterprise Linux for x86_64: 9
CPE2.3https://access.redhat.com/errata/RHSA-2022:6963
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.