CVE Database
/

CVE-2017-15896

Back to search

CVE-2017-15896

Published: Dec 11, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

VendorProductVersions

The Node.js Project

Node.js

affected
4.0.0 and higher
affected
6.0.0 and higher
affected
8.0.0 and higher
affected
9.0.0 and higher

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now