Vulnerabilities/

Improper Certificate Validation in xmlhttprequest-ssl

Severity:
High

Description

The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.

Recommendation

Update the xmlhttprequest-ssl package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
xmlhttprequest-ssl
Anything's wrong? Let us know Last updated on November 29, 2023

This issue is available in SmartScanner Professional

See Pricing