CVE-2017-15896: Critical severity Nodejs Node.js vulnerability
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSLread() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15896?
CVE-2017-15896 has a medium severity level that highlights a potential security risk related to SSL_read() functions.
How do I fix CVE-2017-15896?
To fix CVE-2017-15896, upgrade Node.js to a version that is not affected, specifically versions above 8.9.3 or 6.12.3.
Which versions of Node.js are affected by CVE-2017-15896?
CVE-2017-15896 affects Node.js versions from 4.0.0 to 4.8.7, 6.0.0 to 6.12.2, 8.0.0 to 8.8.1, and 9.0.0 to 9.2.1.
Is CVE-2017-15896 related to any other vulnerabilities?
Yes, CVE-2017-15896 is related to OpenSSL vulnerability CVE-2017-3737 concerning TLS handshake failures.
What can happen if CVE-2017-15896 is exploited?
If exploited, CVE-2017-15896 could allow an active network attacker to bypass TLS authentication and encryption.