CVE-2021-22939
Summary
| CVE | CVE-2021-22939 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-16 19:15:00 UTC |
| Updated | 2024-01-05 10:15:00 UTC |
| Description | If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159398 Oracle Enterprise Linux Security Update for nodejs:12 (ELSA-2021-3623)
- 159408 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2021-3666)
- 180328 Debian Security Update for nodejs (CVE-2021-22939)
- 181111 Debian Security Update for nodejs (DLA 3137-1)
- 239590 Red Hat Update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon (RHSA-2021:3281)
- 239591 Red Hat Update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon (RHSA-2021:3280)
- 239645 Red Hat Update for nodejs:12 (RHSA-2021:3623)
- 239654 Red Hat Update for nodejs:12 (RHSA-2021:3639)
- 239655 Red Hat Update for nodejs:12 (RHSA-2021:3638)
- 239658 Red Hat Update for nodejs:14 (RHSA-2021:3666)
- 375786 Node.js Remote Code Execution Vulnerability Aug 2021
- 375877 Kibana Multiple Security Vulnerabilities (ESA-2021-21, ESA-2021-22, ESA-2021-24)
- 376257 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJAN2022)
- 377157 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2021:0072)
- 500444 Alpine Linux Security Update for nodejs
- 501453 Alpine Linux Security Update for nodejs
- 501884 Alpine Linux Security Update for nodejs-current
- 502123 Alpine Linux Security Update for nodejs-current
- 504207 Alpine Linux Security Update for nodejs
- 505102 Alpine Linux Security Update for nodejs-current
- 690032 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (b092bd4f-1b16-11ec-9d9d-0022489ad614)
- 710820 Gentoo Linux c-ares Multiple Vulnerabilities (GLSA 202401-02)
- 751061 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2021:2875-1)
- 751071 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2021:1214-1)
- 751093 OpenSUSE Security Update for nodejs10 (openSUSE-SU-2021:2953-1)
- 751112 OpenSUSE Security Update for nodejs10 (openSUSE-SU-2021:1239-1)
- 751171 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2021:3211-1)
- 751178 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2021:1313-1)
- 900315 CBL-Mariner Linux Security Update for nodejs 14.17.2
- 901895 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (6744-1)
- 903525 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (5423)
- 940217 AlmaLinux Security Update for nodejs:12 (ALSA-2021:3623)
- 940388 AlmaLinux Security Update for nodejs:14 (ALSA-2021:3666)