CVE-2021-22939

medium

Description

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

References

https://hackerone.com/reports/1278254

https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/

https://security.netapp.com/advisory/ntap-20210917-0003/

https://www.oracle.com/security-alerts/cpuoct2021.html

https://www.oracle.com/security-alerts/cpujan2022.html

https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf

Details

Source: MITRE

Published: 2021-08-16

Updated: 2022-04-06

Type: CWE-295

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM