CVE-2017-15896

Severity

64%

Complexity

99%

Confidentiality

81%

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

CVSS 3.0 Base Score 9.1. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS 2.0 Base Score 6.4. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).

Overview

First reported 7 years ago

2017-12-11 21:29:00

Last updated 5 years ago

2019-10-03 00:03:00

Affected Software

Nodejs Node.js 8.0.0

8.0.0

Nodejs Node.js 8.1.0

8.1.0

Nodejs Node.js 8.1.1

8.1.1

Nodejs Node.js 8.1.2

8.1.2

Nodejs Node.js 8.1.3

8.1.3

nodejs Node.js 8.1.4

8.1.4

nodejs Node.js 8.2.0

8.2.0

nodejs Node.js 8.2.1

8.2.1

nodejs Node.js 8.3.0

8.3.0

nodejs Node.js 8.4.0

8.4.0

nodejs Node.js 8.6.0

8.6.0

nodejs Node.js 8.7.0

8.7.0

Nodejs Node.js 8.8.0

8.8.0

Nodejs Node.js 8.8.1

8.8.1

Nodejs Node.js 8.9.0

8.9.0

Nodejs Node.js 8.9.1

8.9.1

Nodejs Node.js 8.9.2

8.9.2

Nodejs Node.js 8.9.3

8.9.3

Nodejs Node.js 9.0.0

9.0.0

Nodejs Node.js 9.1.0

9.1.0

Nodejs Node.js 9.2.0

9.2.0

Nodejs Node.js 9.2.1

9.2.1

Nodejs Node.js 9.3.0

9.3.0

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.