Логотип exploitDog
bind:CVE-2021-31597
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-31597

Количество 5

Количество 5

ubuntu логотип

CVE-2021-31597

почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
EPSS: Низкий
redhat логотип

CVE-2021-31597

почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
EPSS: Низкий
nvd логотип

CVE-2021-31597

почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
EPSS: Низкий
debian логотип

CVE-2021-31597

почти 5 лет назад

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-72mh-269x-7mh5

больше 4 лет назад

Improper Certificate Validation in xmlhttprequest-ssl

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

CVSS3: 9.4
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-31597

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...

CVSS3: 9.4
0%
Низкий
почти 5 лет назад
github логотип
GHSA-72mh-269x-7mh5

Improper Certificate Validation in xmlhttprequest-ssl

CVSS3: 9.4
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу