yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads...
Low severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 20, 2023
Description
Published by the National Vulnerability Database
May 15, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 20, 2023
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.
References