First published: Wed Aug 11 2021(Updated: )
A flaw was found in Node.js. If the Node.js HTTPS API is used incorrectly and "undefined" is passed for the "rejectUnauthorized" parameter, no error is returned, and the connections to servers with an expired certificate are accepted. The highest threat from this vulnerability is to integrity.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-nodejs14-nodejs | <0:14.17.5-1.el7 | 0:14.17.5-1.el7 |
redhat/rh-nodejs12-nodejs | <0:12.22.5-1.el7 | 0:12.22.5-1.el7 |
redhat/rh-nodejs12-nodejs-nodemon | <0:2.0.3-5.el7 | 0:2.0.3-5.el7 |
Nodejs Node.js | >=12.0.0<12.22.5 | |
Nodejs Node.js | >=14.0.0<14.17.5 | |
Nodejs Node.js | >=16.0.0<16.6.2 | |
Oracle GraalVM | =20.3.3 | |
Oracle GraalVM | =21.2.0 | |
Oracle Jd Edwards Enterpriseone Tools | <=9.2.6.1 | |
Oracle MySQL Cluster | <=8.0.26 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.57 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.58 | |
Oracle PeopleSoft Enterprise PeopleTools | =8.59 | |
Netapp Nextgen Api | ||
Siemens Sinec Infrastructure Network Services | <1.0.1.1 | |
Debian Debian Linux | =10.0 | |
redhat/nodejs | <12.22.5 | 12.22.5 |
redhat/nodejs | <14.17.5 | 14.17.5 |
redhat/nodejs | <16.6.2 | 16.6.2 |
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-22939 is a vulnerability in Node.js where if the HTTPS API is used incorrectly and "undefined" is passed for the "rejectUnauthorized" parameter, connections to servers with an expired certificate are accepted.
The severity of CVE-2021-22939 is low with a CVSS score of 3.7.
CVE-2021-22939 allows connections to servers with an expired certificate to be accepted if the HTTPS API is used incorrectly.
Node.js versions 12.22.5, 14.17.5, and 16.6.2 are affected by CVE-2021-22939.
To fix CVE-2021-22939, upgrade Node.js to version 12.22.5, 14.17.5, or 16.6.2.