CVE-2020-8172

Name
CVE-2020-8172
Description
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://hackerone.com/reports/811502
Vendor Advisory https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/
CONFIRM https://security.netapp.com/advisory/ntap-20200625-0002/
MISC https://www.oracle.com/security-alerts/cpujul2020.html
MISC https://www.oracle.com/security-alerts/cpuoct2020.html
GENTOO https://security.gentoo.org/glsa/202101-07
MISC https://www.oracle.com/security-alerts/cpujan2021.html
N/A https://www.oracle.com//security-alerts/cpujul2021.html
MISC https://www.oracle.com/security-alerts/cpuapr2022.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* node.js >= 12.0.0 < 12.18.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* node.js >= 14.0.0 < 14.4.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* nodejs >= 12.0.0 < 12.18.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* nodejs >= 14.0.0 < 14.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nodejs-current edge-community 14.4.0-r0 None fixed
nodejs-current 3.22-community 14.4.0-r0 None fixed
nodejs-current 3.21-community 14.4.0-r0 None fixed
nodejs-current 3.20-community 14.4.0-r0 None fixed
nodejs-current 3.19-community 14.4.0-r0 None fixed
nodejs-current 3.18-community 14.4.0-r0 None fixed
nodejs-current 3.17-community 14.4.0-r0 None fixed
nodejs edge-main 12.18.0-r0 None fixed
nodejs edge-main 12.15.0-r0 None possibly vulnerable
nodejs 3.22-main 12.18.0-r0 None fixed
nodejs 3.22-main 12.15.0-r0 None possibly vulnerable
nodejs 3.21-main 12.18.0-r0 None fixed
nodejs 3.21-main 12.15.0-r0 None possibly vulnerable
nodejs 3.20-main 12.18.0-r0 None fixed
nodejs 3.20-main 12.15.0-r0 None possibly vulnerable
nodejs 3.19-main 12.18.0-r0 None fixed
nodejs 3.19-main 12.15.0-r0 None possibly vulnerable
nodejs 3.18-main 12.18.0-r0 None fixed
nodejs 3.17-main 12.18.0-r0 None fixed
nodejs 3.12-main 12.18.3-r0 None fixed
nodejs 3.11-main 12.20.1-r0 None fixed