TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
[
{
"product": "https://github.com/nodejs/node",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "12.18.0,14.4.0"
}
]
}
]
hackerone.com/reports/811502
nodejs.org/en/blog/vulnerability/june-2020-security-releases/
security.gentoo.org/glsa/202101-07
security.netapp.com/advisory/ntap-20200625-0002/
www.oracle.com//security-alerts/cpujul2021.html
www.oracle.com/security-alerts/cpuapr2022.html
www.oracle.com/security-alerts/cpujan2021.html
www.oracle.com/security-alerts/cpujul2020.html
www.oracle.com/security-alerts/cpuoct2020.html