{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"OpenSSL Command Injection Vulnerability (CVE-2022-1292)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2022-00012","status":"final","version":"24","initial_release_date":"2022-05-20T15:17:37+00:00","current_release_date":"2026-07-28T01:17:08.112744+00:00","revision_history":[{"date":"2022-05-20T15:17:37+00:00","number":"24","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2022-00012"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2022-1292"}],"notes":[{"category":"summary","text":"On May 3 2022, OpenSSL published a security advisory disclosing a command injection vulnerability in the c_rehash script included with the library. Some operating systems automatically execute this script as a part of normal operations which could allow an attacker to execute arbitrary commands with elevated privileges.\n\nNo WatchGuard products are affected by this vulnerability.","title":"Summary"}]}}