Lucene search

K
redhatcveRedhat.comRH:CVE-2016-7099
HistorySep 28, 2016 - 6:47 a.m.

CVE-2016-7099

2016-09-2806:47:27
redhat.com
access.redhat.com
11

0.003 Low

EPSS

Percentile

70.2%

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.