VDB
RHSA-2022%3A8913
RHSA-2022%3A8913
PUBLISHED
CVSS 6.699999809265137 MEDIUM
A flaw was found in OpenSSL. The `c_rehash` script does not properly sanitize shell meta-characters to prevent command injection. Some operating systems distribute this script in a manner where it is automatically executed. This flaw allows an attacker to execute arbitrary commands with the privileges of the script on these operating systems.
Risk Scores
CVSS 3.1
6.699999809265137
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | JWS 5.7.1 release |
Timeline
- Dec 12, 2022 CVE Published
- Mar 18, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2022:8913 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=5.7 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2081494 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2097310 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_8913.json advisory
- https://access.redhat.com/security/cve/CVE-2022-1292 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1292 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1292 advisory
- https://www.openssl.org/news/secadv/20220503.txt advisory
- https://access.redhat.com/security/cve/CVE-2022-2068 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-2068 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2068 advisory
- https://www.openssl.org/news/secadv/20220621.txt advisory