Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frj6-5rhh-vwfw

Опубликовано: 31 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 6.5

Описание

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

EPSS

Процентиль: 2%
0.00124
Низкий

8.3 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 6.5
ubuntu
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
redhat
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
nvd
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised HTTPS connections.

CVSS3: 6.5
debian
16 дней назад

Nodemailer before 8.0.8 disables TLS certificate verification in lib/f ...

EPSS

Процентиль: 2%
0.00124
Низкий

8.3 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-295