ZeroHour

CVE-2021-22939

PoC
CVSS 3.1
5.3 medium
EPSS
15%p96
Published
()
Modified
Description

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

Vendors
nodejsoraclenetappsiemensdebian
Products
node.js, graalvm, jd edwards enterpriseone tools, mysql cluster, peoplesoft enterprise peopletools, nextgen api, sinec infrastructure network services, debian linux
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.