CVE Vulnerabilities

CVE-2016-7099

Published: Oct 10, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
7.4 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

Affected Software

NameVendorStart VersionEnd Version
Node.jsNodejs0.10.0 (including)0.10.0 (including)
Node.jsNodejs0.10.1 (including)0.10.1 (including)
Node.jsNodejs0.10.2 (including)0.10.2 (including)
Node.jsNodejs0.10.3 (including)0.10.3 (including)
Node.jsNodejs0.10.4 (including)0.10.4 (including)
Node.jsNodejs0.10.5 (including)0.10.5 (including)
Node.jsNodejs0.10.6 (including)0.10.6 (including)
Node.jsNodejs0.10.7 (including)0.10.7 (including)
Node.jsNodejs0.10.8 (including)0.10.8 (including)
Node.jsNodejs0.10.9 (including)0.10.9 (including)
Node.jsNodejs0.10.10 (including)0.10.10 (including)
Node.jsNodejs0.10.11 (including)0.10.11 (including)
Node.jsNodejs0.10.12 (including)0.10.12 (including)
Node.jsNodejs0.10.13 (including)0.10.13 (including)
Node.jsNodejs0.10.14 (including)0.10.14 (including)
Node.jsNodejs0.10.15 (including)0.10.15 (including)
Node.jsNodejs0.10.16 (including)0.10.16 (including)
Node.jsNodejs0.10.16-isaacs-manual (including)0.10.16-isaacs-manual (including)
Node.jsNodejs0.10.17 (including)0.10.17 (including)
Node.jsNodejs0.10.18 (including)0.10.18 (including)
Node.jsNodejs0.10.19 (including)0.10.19 (including)
Node.jsNodejs0.10.20 (including)0.10.20 (including)
Node.jsNodejs0.10.21 (including)0.10.21 (including)
Node.jsNodejs0.10.22 (including)0.10.22 (including)
Node.jsNodejs0.10.23 (including)0.10.23 (including)
Node.jsNodejs0.10.24 (including)0.10.24 (including)
Node.jsNodejs0.10.25 (including)0.10.25 (including)
Node.jsNodejs0.10.26 (including)0.10.26 (including)
Node.jsNodejs0.10.27 (including)0.10.27 (including)
Node.jsNodejs0.10.28 (including)0.10.28 (including)
Node.jsNodejs0.10.29 (including)0.10.29 (including)
Node.jsNodejs0.10.30 (including)0.10.30 (including)
Node.jsNodejs0.10.31 (including)0.10.31 (including)
Node.jsNodejs0.10.32 (including)0.10.32 (including)
Node.jsNodejs0.10.33 (including)0.10.33 (including)
Node.jsNodejs0.10.34 (including)0.10.34 (including)
Node.jsNodejs0.10.35 (including)0.10.35 (including)
Node.jsNodejs0.10.36 (including)0.10.36 (including)
Node.jsNodejs0.10.37 (including)0.10.37 (including)
Node.jsNodejs0.10.38 (including)0.10.38 (including)
Node.jsNodejs0.10.39 (including)0.10.39 (including)
Node.jsNodejs0.10.40 (including)0.10.40 (including)
Node.jsNodejs0.10.41 (including)0.10.41 (including)
Node.jsNodejs0.10.42 (including)0.10.42 (including)
Node.jsNodejs0.10.43 (including)0.10.43 (including)
Node.jsNodejs0.10.44 (including)0.10.44 (including)
Node.jsNodejs0.10.45 (including)0.10.45 (including)
Node.jsNodejs0.10.46 (including)0.10.46 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-nodejs4-http-parser-0:2.7.0-2.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHatrh-nodejs4-nodejs-0:4.6.2-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-nodejs4-http-parser-0:2.7.0-2.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSRedHatrh-nodejs4-nodejs-0:4.6.2-4.el6*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-nodejs4-http-parser-0:2.7.0-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-nodejs4-nodejs-0:4.6.2-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-nodejs4-http-parser-0:2.7.0-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHatrh-nodejs4-nodejs-0:4.6.2-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-nodejs4-http-parser-0:2.7.0-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSRedHatrh-nodejs4-nodejs-0:4.6.2-4.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-nodejs4-http-parser-0:2.7.0-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSRedHatrh-nodejs4-nodejs-0:4.6.2-4.el7*
NodejsUbuntuartful*
NodejsUbuntuesm-apps/xenial*
NodejsUbuntuesm-infra-legacy/trusty*
NodejsUbuntuprecise*
NodejsUbuntutrusty*
NodejsUbuntutrusty/esm*
NodejsUbuntuupstream*
NodejsUbuntuxenial*
NodejsUbuntuyakkety*
NodejsUbuntuzesty*

References