Vulnerability Description
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
CVSS Score
7.4
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | >= 12.0.0, < 12.18.0 |
| Oracle | Banking Extensibility Workbench | 14.3.0 |
| Oracle | Blockchain Platform | < 21.1.2 |
| Oracle | Graalvm | 19.3.2 |
| Oracle | Mysql Cluster | <= 7.3.30 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/811502ExploitThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/Vendor Advisory
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200625-0002/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlNot ApplicableThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatchThird Party Advisory
- https://hackerone.com/reports/811502ExploitThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/Vendor Advisory
- https://security.gentoo.org/glsa/202101-07Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200625-0002/Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlNot ApplicableThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-8172?
CVE-2020-8172 is a vulnerability with a CVSS score of 7.4 (HIGH). TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
How severe is CVE-2020-8172?
CVE-2020-8172 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8172?
Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js, Oracle Banking Extensibility Workbench, Oracle Blockchain Platform, Oracle Graalvm, Oracle Mysql Cluster.