yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks. References: https://github.com/erlyaws/yaws/blob/c0fd79f17d52628fcec527da7fa3e788c283c445/src/yaws_config.erl#L2068-L2075 https://github.com/erlyaws/yaws/releases https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70 https://sweet32.info/
Created yaws tracking bugs for this issue: Affects: epel-7 [bug 1839817] Affects: fedora-all [bug 1839816]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.