CVE-2020-8172: High severity langgenius dify node.js vulnerability
Published Jun 2, 2020
·Updated
A TLS Hostname verification bypass vulnerability exists in NodeJS. This flaw allows an attacker to bypass TLS Hostname verification when a TLS client reuses HTTPS sessions.
Other sources
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
Affected Software
16 affected componentsFixes available
redhat/rh-nodejs12-nodejs<0:12.18.2-1.el7
0:12.18.2-1.el7
debian/nodejs
10.24.0~dfsg-1~deb10u110.24.0~dfsg-1~deb10u312.22.12~dfsg-1~deb11u418.13.0+dfsg1-1
redhat/nodejs<12.18.0
12.18.0
redhat/nodejs<14.4.0
14.4.0
Nodejs Node.js>=12.0.0<12.18.0
Nodejs Node.js>=14.0.0<14.4.0
Oracle Banking Extensibility Workbench=14.3.0
Oracle Banking Extensibility Workbench=14.4.0
Oracle Blockchain Platform<21.1.2
Oracle GraalVM=19.3.2
Oracle GraalVM=20.1.0
Oracle MySQL Cluster<=7.3.30
Oracle MySQL Cluster>=7.4.0<=7.4.29
Oracle MySQL Cluster>=7.5.0<=7.5.19
Oracle MySQL Cluster>=7.6.0<=7.6.15
Oracle MySQL Cluster>=8.0.0<=8.0.21
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jun 2, 2020
CVE Published
12:00 AM
Jun 8, 2020
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
DescriptionWeakness
Parent advisories
This vulnerability appears in the following advisories.