High severity7.4NVD Advisory· Published Jun 8, 2020· Updated Jun 17, 2026
CVE-2020-8172
CVE-2020-8172
Description
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_extensibility_workbench:14.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*Range: <21.1.2
cpe:2.3:a:oracle:graalvm:19.3.2:*:*:*:enterprise:*:*:*+ 1 more
- cpe:2.3:a:oracle:graalvm:19.3.2:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:graalvm:20.1.0:*:*:*:enterprise:*:*:*
- node/nodedescription
- osv-coords6 versionspkg:bitnami/nodepkg:bitnami/node-minpkg:rpm/almalinux/nodejs-nodemonpkg:rpm/almalinux/nodejs-packagingpkg:rpm/opensuse/nodejs14&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nodejs12&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012
>= 12.0.0, < 12.18.0+ 5 more
- (no CPE)range: >= 12.0.0, < 12.18.0
- (no CPE)range: >= 12.0.0, < 12.18.0
- (no CPE)range: < 1.18.3-1.module_el8.3.0+2023+d2377ea3
- (no CPE)range: < 17-3.module_el8.4.0+2224+b07ac28e
- (no CPE)range: < 14.17.5-1.2
- (no CPE)range: < 12.18.0-1.14.1
Patches
Vulnerability mechanics
References
9- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujan2021.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpujul2020.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuoct2020.htmlnvdPatchThird Party Advisory
- hackerone.com/reports/811502nvdExploitThird Party Advisory
- nodejs.org/en/blog/vulnerability/june-2020-security-releases/nvdVendor Advisory
- security.gentoo.org/glsa/202101-07nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20200625-0002/nvdThird Party Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdNot ApplicableThird Party Advisory
News mentions
0No linked articles in our index yet.