OpenSSL 3.0.7 update assessment

Summary The vulnerability in the OpenSSL Security Advisory of Dec 13 2022 do not affect any active Node.js release lines. Analysis Our assessment of the security advisory is: X.509 Policy Constraints Double Locking (CVE-2022-3996) Node.js doesn’t call OpenSSL as a separate process (so the possibility to use the 1-policy flag Read more…