If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/ | patch vendor advisory |
https://hackerone.com/reports/1278254 | issue tracking exploit third party advisory |
https://www.oracle.com/security-alerts/cpuoct2021.html | third party advisory patch |
https://security.netapp.com/advisory/ntap-20210917-0003/ | third party advisory |
https://www.oracle.com/security-alerts/cpujan2022.html | third party advisory patch |
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | third party advisory patch |
https://www.oracle.com/security-alerts/cpujul2022.html | third party advisory patch |
https://lists.debian.org/debian-lts-announce/2022/10/msg00006.html | issue tracking mailing list third party advisory |
https://security.gentoo.org/glsa/202401-02 | vendor advisory |