Vulnerabilities > Xmlhttprequest SSL Project

DATE CVE VULNERABILITY TITLE RISK
2021-04-23 CVE-2021-31597 Improper Certificate Validation vulnerability in Xmlhttprequest-Ssl Project Xmlhttprequest-Ssl
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js.
network
low complexity
xmlhttprequest-ssl-project CWE-295
critical
9.4