← All CVEs

CVE-2021-22939

medium · 5.3

If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.

5.3
CVSS
14.7%
EPSS (exploit prob.)
97th
EPSS percentile
2021-08-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-295

Affected products

VendorProductAffected versions
nodejsnode.js>= 12.0.0, < 12.22.5
nodejsnode.js>= 14.0.0, < 14.17.5
nodejsnode.js>= 16.0.0, < 16.6.2
oraclegraalvm20.3.3
oraclegraalvm21.2.0
oraclejd_edwards_enterpriseone_tools<= 9.2.6.1
oraclemysql_cluster<= 8.0.26
oraclepeoplesoft_enterprise_peopletools8.57
oraclepeoplesoft_enterprise_peopletools8.58
oraclepeoplesoft_enterprise_peopletools8.59
netappnextgen_apiall versions
siemenssinec_infrastructure_network_services< 1.0.1.1
debiandebian_linux10.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-22939