« List of all CVEs

CVE-2020-8172

Published: 6/8/2020 Last updated: 8/4/2024 Reserved: 1/28/2020

TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

CNA assigner: hackerone (36234546-b8fa-4601-9d6f-f4e334aa8ea1) Requested by: n/a

Opam packages affected (1)

conf-npm

Products affected (2)

Product Vendor Version
https://github.com/nodejs/node n/a < 18.4
https://github.com/nodejs/node n/a <= 14.0.0-RC4

References (36)