CVE Vulnerabilities

CVE-2017-15896

Published: Dec 11, 2017 | Modified: Aug 16, 2022
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

Affected Software

Name Vendor Start Version End Version
Node.js Nodejs 4.0.0 (including) 4.1.2 (including)
Node.js Nodejs 4.2.0 (including) 4.8.7 (excluding)
Node.js Nodejs 6.0.0 (including) 6.8.1 (including)
Node.js Nodejs 6.9.0 (including) 6.12.2 (excluding)
Node.js Nodejs 8.0.0 (including) 8.8.1 (including)
Node.js Nodejs 8.9.0 (including) 8.9.3 (excluding)
Node.js Nodejs 9.0.0 (including) 9.2.1 (excluding)

References