TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
2020-06-08T14:15:13.213
2024-11-21T05:38:26.007
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nodejs | node.js | < 12.18.0 | Yes |
Application | nodejs | node.js | < 14.4.0 | Yes |
Application | oracle | banking_extensibility_workbench | 14.3.0 | Yes |
Application | oracle | banking_extensibility_workbench | 14.4.0 | Yes |
Application | oracle | blockchain_platform | < 21.1.2 | Yes |
Application | oracle | graalvm | 19.3.2 | Yes |
Application | oracle | graalvm | 20.1.0 | Yes |
Application | oracle | mysql_cluster | ≤ 7.3.30 | Yes |
Application | oracle | mysql_cluster | ≤ 7.4.29 | Yes |
Application | oracle | mysql_cluster | ≤ 7.5.19 | Yes |
Application | oracle | mysql_cluster | ≤ 7.6.15 | Yes |
Application | oracle | mysql_cluster | ≤ 8.0.21 | Yes |