Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-22939

Опубликовано: 16 авг. 2021
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 5
CVSS3: 5.3

Описание

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

18.7.0+dfsg-5ubuntu1
esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

12.22.9~dfsg-1ubuntu3.6
esm-apps/noble

not-affected

18.7.0+dfsg-5ubuntu1
esm-apps/resolute

not-affected

18.7.0+dfsg-5ubuntu1
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

not-affected

code not present

Показывать по

EPSS

Процентиль: 96%
0.1473
Средний

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
почти 5 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
nvd
почти 5 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
msrc
почти 5 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter no error was returned and connections to servers with an expired certificate would have been accepted.

CVSS3: 5.3
debian
почти 5 лет назад

If the Node.js https API was used incorrectly and "undefined" was in p ...

CVSS3: 5.3
github
около 4 лет назад

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

EPSS

Процентиль: 96%
0.1473
Средний

5 Medium

CVSS2

5.3 Medium

CVSS3