QID 982081
QID 982081: Nodejs (npm) Security Update for xmlhttprequest-ssl (GHSA-72mh-269x-7mh5)
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-72mh-269x-7mh5 for updates pertaining to this vulnerability.
Vendor References
- GHSA-72mh-269x-7mh5 -
github.com/advisories/GHSA-72mh-269x-7mh5
CVEs related to QID 982081
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-72mh-269x-7mh5 | xmlhttprequest-ssl |
|