Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-31597

Опубликовано: 23 апр. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.4

Описание

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
groovy

ignored

end of life
hirsute

ignored

end of life
impish

DNE

jammy

DNE

Показывать по

EPSS

Процентиль: 58%
0.00371
Низкий

7.5 High

CVSS2

9.4 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.4
redhat
почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
nvd
почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
debian
почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...

CVSS3: 9.4
github
больше 4 лет назад

Improper Certificate Validation in xmlhttprequest-ssl

EPSS

Процентиль: 58%
0.00371
Низкий

7.5 High

CVSS2

9.4 Critical

CVSS3