Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-32210

Опубликовано: 14 июл. 2022
Источник: debian
EPSS Низкий

Описание

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-undicifixed5.6.1+dfsg1+~cs18.9.16-1package

Примечания

  • https://github.com/advisories/GHSA-pgw7-wx7w-2w33

EPSS

Процентиль: 32%
0.00127
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

CVSS3: 6.5
nvd
больше 3 лет назад

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

CVSS3: 7.7
github
больше 3 лет назад

ProxyAgent vulnerable to MITM

EPSS

Процентиль: 32%
0.00127
Низкий