Количество 6
Количество 6
CVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
CVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
CVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
CVE-2021-31597
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ...
GHSA-72mh-269x-7mh5
Improper Certificate Validation in xmlhttprequest-ssl
BDU:2026-10996
Уязвимость библиотеки для веб-запросов node-XMLHttpRequest, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-31597 The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected. | CVSS3: 9.4 | 2% Низкий | больше 5 лет назад | |
CVE-2021-31597 The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected. | CVSS3: 9.4 | 2% Низкий | больше 5 лет назад | |
CVE-2021-31597 The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected. | CVSS3: 9.4 | 2% Низкий | больше 5 лет назад | |
CVE-2021-31597 The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL c ... | CVSS3: 9.4 | 2% Низкий | больше 5 лет назад | |
GHSA-72mh-269x-7mh5 Improper Certificate Validation in xmlhttprequest-ssl | CVSS3: 9.4 | 2% Низкий | больше 5 лет назад | |
BDU:2026-10996 Уязвимость библиотеки для веб-запросов node-XMLHttpRequest, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 9.4 | 2% Низкий | больше 5 лет назад |
Уязвимостей на страницу