QID 981229
QID 981229: Nodejs (npm) Security Update for tiny-json-http (GHSA-7h42-5vj2-cq39)
brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-7h42-5vj2-cq39 for updates pertaining to this vulnerability.
Vendor References
- GHSA-7h42-5vj2-cq39 -
github.com/advisories/GHSA-7h42-5vj2-cq39
CVEs related to QID 981229
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7h42-5vj2-cq39 | tiny-json-http |
|