Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25640
HistoryJun 09, 2020 - 2:53 a.m.

Hostname Verification Bypass

2020-06-0902:53:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.003 Low

EPSS

Percentile

66.0%

node is vulnerable to Hostname Verification Bypass. When multiple connections to the same server are opened, TLS sessions from client side can be reused, leading to a bypass of verification of host certificate and allowing an authorized connection with the cached session ticket.