Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h42-5vj2-cq39

Опубликовано: 13 мар. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

tiny-json-http missing SSL certificate validation

brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.

Пакеты

Наименование

tiny-json-http

npm
Затронутые версииВерсия исправления

>= 1.0.1, < 7.0.0

7.0.0

EPSS

Процентиль: 39%
0.0017
Низкий

8.1 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.1
nvd
почти 8 лет назад

brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.

EPSS

Процентиль: 39%
0.0017
Низкий

8.1 High

CVSS3

Дефекты

CWE-295