CVE-2016-7099
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to…
Does this matter?
Lower severity and a low EPSS score (2.84%). Track it; it rarely justifies an emergency change on its own.
Description
The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.84% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- nodejs/node.js · suse/linux enterprise
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0002.html
- http://www.securityfocus.com/bid/93191Third Party Advisory, VDB Entry
- https://github.com/nodejs/node/commit/743f0c916469f3129dfae406fa104dc46782e20bIssue Tracking, Patch
- https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0002.html
- http://www.securityfocus.com/bid/93191Third Party Advisory, VDB Entry
- https://github.com/nodejs/node/commit/743f0c916469f3129dfae406fa104dc46782e20bIssue Tracking, Patch
- https://nodejs.org/en/blog/vulnerability/september-2016-security-releases/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.