Related Vulnerabilities: CVE-2020-12872  

yaws_config.erl in Yaws through 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.

Severity Medium

Remote Yes

Type Information disclosure

Description

yaws_config.erl in Yaws through 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks.

AVG-1161 yaws 2.0.7-1 Medium Vulnerable

https://sweet32.info/
https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70