CVE-2021-22939
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
Affected (13)
Products: Nodejs: Node.js · Oracle: Graalvm, Jd Edwards Enterpriseone Tools, Mysql Cluster, Peoplesoft Enterprise Peopletools · Netapp: Nextgen Api · +2 more
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.3.3 | |
| Up to 9.2.6.1 | |
| Up to 8.0.26 | |
| Version 8.57 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.1.1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (18)
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
ExploitIssue TrackingThird Party Advisory
Source: support@hackerone.com
Issue TrackingThird Party Advisory
Source: support@hackerone.com
PatchVendor Advisory
Source: support@hackerone.com
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.