CVE-2020-12872 - log back

CVE-2020-12872 edited at 16 May 2020 19:06:30
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
CVE-2020-12872 edited at 16 May 2020 19:05:52
Description
+ yaws_config.erl in Yaws through 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.
References
+ https://sweet32.info/
+ https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70
Notes
CVE-2020-12872 created at 16 May 2020 18:59:48