Vulnerabilities/

Insecure Default Configuration in redbird

Severity:
Medium

Description

Versions of redbird prior to 0.9.1 have a vulnerable default configuration of allowing TLS 1.0 connections on lib/proxy.js. The package does not provide an option to disable TLS 1.0 which is deprecated and vulnerable.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
redbird
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing