The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
2022-05-03T16:15:18.823
2025-05-05T17:17:33.950
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openssl | openssl | < 1.0.2ze | Yes |
Application | openssl | openssl | < 1.1.1o | Yes |
Application | openssl | openssl | < 3.0.3 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Operating System | debian | debian_linux | 11.0 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | clustered_data_ontap | - | Yes |
Application | netapp | clustered_data_ontap_antivirus_connector | - | Yes |
Application | netapp | oncommand_insight | - | Yes |
Application | netapp | oncommand_workflow_automation | - | Yes |
Application | netapp | santricity_smi-s_provider | - | Yes |
Application | netapp | smi-s_provider | - | Yes |
Application | netapp | snapcenter | - | Yes |
Application | netapp | snapmanager | - | Yes |
Application | netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | - | Yes |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Operating System | netapp | a700s_firmware | - | Yes |
Hardware | netapp | a700s | - | No |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h300e_firmware | - | Yes |
Hardware | netapp | h300e | - | No |
Operating System | netapp | h500e_firmware | - | Yes |
Hardware | netapp | h500e | - | No |
Operating System | netapp | h700e_firmware | - | Yes |
Hardware | netapp | h700e | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | netapp | aff_8300_firmware | - | Yes |
Hardware | netapp | aff_8300 | - | No |
Operating System | netapp | fas_8300_firmware | - | Yes |
Hardware | netapp | fas_8300 | - | No |
Operating System | netapp | aff_8700_firmware | - | Yes |
Hardware | netapp | aff_8700 | - | No |
Operating System | netapp | fas_8700_firmware | - | Yes |
Hardware | netapp | fas_8700 | - | No |
Operating System | netapp | aff_a400_firmware | - | Yes |
Hardware | netapp | aff_a400 | - | No |
Operating System | netapp | fabric-attached_storage_a400_firmware | - | Yes |
Hardware | netapp | fabric-attached_storage_a400 | - | No |
Operating System | netapp | a250_firmware | - | Yes |
Hardware | netapp | a250 | - | No |
Operating System | netapp | aff_500f_firmware | - | Yes |
Hardware | netapp | aff_500f | - | No |
Operating System | netapp | fas_500f_firmware | - | Yes |
Hardware | netapp | fas_500f | - | No |
Application | oracle | enterprise_manager_ops_center | 12.4.0.0 | Yes |
Application | oracle | mysql_server | ≤ 5.7.38 | Yes |
Application | oracle | mysql_server | ≤ 8.0.29 | Yes |
Application | oracle | mysql_workbench | ≤ 8.0.29 | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |