nodejs: TLS session reuse can lead to hostname verification bypass
Published Jun 8, 2020
7.4
HIGHCVSS 3.1
EPSS 6.07%
Description
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
Affected products
No data.
Configuration 1
Configuration 2
- 14.3.0
- 14.4.0
- < 21.1.2
- 19.3.2
- 20.1.0
- ≤ 7.3.30
- ≥ 7.4.0 · ≤ 7.4.29
- ≥ 7.5.0 · ≤ 7.5.19
- ≥ 7.6.0 · ≤ 7.6.15
- ≥ 8.0.0 · ≤ 8.0.21
No data.
Red Hat Enterprise Linux 8
nodejs:12-8020020200630155331.4cda2c84
Fixed · RHSA-2020:2852
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:12-8010020200630154708.c27ad7f8
Fixed · RHSA-2020:2847
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Enterprise Linux 8
nodejs:10/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
Red Hat Quay 3
nodejs
Fix deferred
Red Hat Software Collections
rh-nodejs10-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:12-8020020200630155331.4cda2c84 | Fixed | RHSA-2020:2852 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:12-8010020200630154708.c27ad7f8 | Fixed | RHSA-2020:2847 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Enterprise Linux 8 | nodejs:10/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
| Red Hat Quay 3 | nodejs | Fix deferred | n/a |
| Red Hat Software Collections | rh-nodejs10-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affects the TLS 1.2 protocol, not TLS 1.3. This issue does not affect NodeJS 10. Red Hat Quay installed NodeJS as a dependency of Yarn. It does not use NodeJS at runtime, but executes Javascript on the client's browser instead. Therefore the impact of this vulnerability on Red Hat Quay is low.
References (14)
- https://access.redhat.com/security/cve/CVE-2020-8172 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1845247 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29056 Advisory
- https://hackerone.com/reports/811502 x_refsource_MISCExploitThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/ x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8172
- https://security.gentoo.org/glsa/202101-07 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200625-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8172
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCNot ApplicableThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data