CVE-2021-22939
5.3
MEDIUM
CVSS 3.1
EPSS 14.7%
Description
If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.
How to fix CVE-2021-22939
To remediate CVE-2021-22939, upgrade the affected package to a fixed version below.
- Alpine/nodejs—upgrade to 12.22.5-r0 or later
- Bitnami/node—upgrade to 12.22.5 or later
- —upgrade to 12.22.5 or later
- —upgrade to 12.22.5~dfsg-2~11u1 or later
Is CVE-2021-22939 being exploited?
Moderate — EPSS is 14.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (4)
- from 0, < 12.22.5-r0
- >= 12.0.0, < 12.22.5, >= 14.0.0, < 14.17.5, >= 16.0.0, < 16.6.2
- >= 12.0.0, < 12.22.5, >= 14.0.0, < 14.17.5, >= 16.0.0, < 16.6.2
- from 0, < 12.22.5~dfsg-2~11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |