Medium severity5.5NVD Advisory· Published May 15, 2020· Updated Jun 17, 2026
CVE-2020-12872
CVE-2020-12872
Description
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if running on an Erlang/OTP virtual machine with a version less than 21.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Yaws/Yawsdescription
Patches
Vulnerability mechanics
References
5- github.com/erlyaws/yaws/blob/c0fd79f17d52628fcec527da7fa3e788c283c445/src/yaws_config.erlnvdExploitThird Party Advisory
- github.com/erlyaws/yaws/issues/402nvdIssue TrackingThird Party Advisory
- github.com/erlyaws/yaws/releasesnvdRelease NotesThird Party Advisory
- sweet32.infonvdThird Party Advisory
- medium.com/%40charlielabs101/cve-2020-12872-df315411aa70nvd
News mentions
0No linked articles in our index yet.