CVE-2020-8172

Severity
7.4HIGH
EPSS
1.2%
top 21.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateMay 24

Description

TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages7 packages

NVDnodejs/node.js12.0.012.18.0+1
Alpinenodejs< 12.20.1-r0+12
CVEListV5https://github.com/nodejs/node12.18.0,14.4.0
NVDoracle/mysql_cluster7.4.07.4.29+4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-98vx-jqrx-7mq2: TLS session reuse can lead to host certificate verification bypass in node version < 122022-05-24
CVEList
CVE-2020-8172: TLS session reuse can lead to host certificate verification bypass in node version < 122020-06-08
OSV
CVE-2020-8172: TLS session reuse can lead to host certificate verification bypass in node version < 122020-06-08

📋Vendor Advisories

2
Red Hat
nodejs: TLS session reuse can lead to hostname verification bypass2020-06-02
Debian
CVE-2020-8172: nodejs - TLS session reuse can lead to host certificate verification bypass in node versi...2020

💬Community

8
Bugzilla
CVE-2020-8172 nodejs:10/nodejs: TLS session reuse can lead to hostname verification bypass [fedora-all]2020-06-08
Bugzilla
CVE-2020-8172 nodejs: TLS session reuse can lead to hostname verification bypass2020-06-08
Bugzilla
CVE-2020-8172 nodejs:12/nodejs: TLS session reuse can lead to hostname verification bypass [fedora-all]2020-06-08
Bugzilla
CVE-2020-8172 nodejs:11/nodejs: TLS session reuse can lead to hostname verification bypass [fedora-all]2020-06-08
Bugzilla
CVE-2020-8172 nodejs:13/nodejs: TLS session reuse can lead to hostname verification bypass [fedora-all]2020-06-08
CVE-2020-8172 (HIGH CVSS 7.4) | TLS session reuse can lead to host | cvebase.io