Логотип exploitDog
bind:CVE-2022-32210
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-32210

Количество 4

Количество 4

ubuntu логотип

CVE-2022-32210

больше 3 лет назад

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-32210

больше 3 лет назад

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-32210

больше 3 лет назад

`Undici.ProxyAgent` never verifies the remote server's certificate, an ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-pgw7-wx7w-2w33

больше 3 лет назад

ProxyAgent vulnerable to MITM

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-32210

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-32210

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-32210

`Undici.ProxyAgent` never verifies the remote server's certificate, an ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pgw7-wx7w-2w33

ProxyAgent vulnerable to MITM

CVSS3: 7.7
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу