cbcvebase.
CVE-2020-8172
published 2020-06-08

CVE-2020-8172: TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiannodejs
httpsgithub.com_nodejs_node
nodejsnode.js>= 12.0.0 < 12.18.012.18.0
nodejsnode.js>= 14.0.0 < 14.4.014.4.0
nodejsnodejs>= 0 < 12.20.1-r012.20.1-r0
nodejsnodejs>= 0 < 12.18.3-r012.18.3-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
nodejsnodejs>= 0 < 12.18.0-r012.18.0-r0
oraclebanking_extensibility_workbench
oraclebanking_extensibility_workbench
oracleblockchain_platform< 21.1.221.1.2
oraclegraalvm
oraclegraalvm
oraclemysql_cluster<= 7.3.30
oraclemysql_cluster7.4.0 – 7.4.29
oraclemysql_cluster7.5.0 – 7.5.19

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH