CVE-2021-31597 Information
Jun 07, 2022
cve
Description
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words no certificate is ever rejected.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Reference
https://people.kingsds.network/wesgarland/xmlhttprequest-ssl-vuln.txt https://github.com/mjwwit/node-XMLHttpRequest/commit/bf53329b61ca6afc5d28f6b8d2dc2e3ca740a9b2 https://github.com/mjwwit/node-XMLHttpRequest/compare/v1.6.0…1.6.1 https://security.netapp.com/advisory/ntap-20210618-0004/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
LOW
Base Severity
9.4
Share on: