Описание
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
Ссылки
- PatchThird Party Advisory
- PatchRelease NotesThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchRelease NotesThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
9.4 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...
Improper Certificate Validation in xmlhttprequest-ssl
EPSS
9.4 Critical
CVSS3
7.5 High
CVSS2