← Back

CVE-2017-15896

nvd nist
Published: Dec 11, 2017Modified: May 13, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

Affected (7)

Products: Nodejs: Node.js
1 product
Node.js
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
From 4.0.0 to 4.1.2
From 6.0.0 to 6.8.1
From 8.0.0 to 8.8.1
From 9.0.0 to 9.2.1
From 4.2.0 to 4.8.7
From 6.9.0 to 6.12.2
From 8.9.0 to 8.9.3

References (2)

Source: cve-request@iojs.org
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory

Timeline

No history available yet.