CVE-2021-22939
PoC —CVSS 3.1
5.3 medium
EPSS
15%p96
Published
()
Modified
Description
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
In the news0 stories
No ingested article mentions this CVE yet.