Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2021-31597

больше 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
EPSS: Низкий
redhat логотип

CVE-2021-31597

больше 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
EPSS: Низкий
nvd логотип

CVE-2021-31597

больше 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
EPSS: Низкий
debian логотип

CVE-2021-31597

больше 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-72mh-269x-7mh5

больше 5 лет назад

Improper Certificate Validation in xmlhttprequest-ssl

CVSS3: 9.4
EPSS: Низкий
fstec логотип

BDU:2026-10996

больше 5 лет назад

Уязвимость библиотеки для веб-запросов node-XMLHttpRequest, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
2%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...

CVSS3: 9.4
2%
Низкий
больше 5 лет назад
github логотип
GHSA-72mh-269x-7mh5

Improper Certificate Validation in xmlhttprequest-ssl

CVSS3: 9.4
2%
Низкий
больше 5 лет назад
fstec логотип
BDU:2026-10996

Уязвимость библиотеки для веб-запросов node-XMLHttpRequest, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.4
2%
Низкий
больше 5 лет назад

Уязвимостей на страницу