UBUNTU-CVE-2021-31597

Source
https://ubuntu.com/security/CVE-2021-31597
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-31597.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-31597
Related
Published
2021-04-23T00:15:00Z
Modified
2025-01-13T10:22:33Z
Severity
  • 9.4 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L CVSS Calculator
Summary
[none]
Details

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

References

Affected packages

Ubuntu:Pro:18.04:LTS / node-xmlhttprequest-ssl

Package

Name
node-xmlhttprequest-ssl
Purl
pkg:deb/ubuntu/node-xmlhttprequest-ssl@1.6.0-1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / node-xmlhttprequest-ssl

Package

Name
node-xmlhttprequest-ssl
Purl
pkg:deb/ubuntu/node-xmlhttprequest-ssl@1.6.0-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.0-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}