CVE-2021-31597 describes a critical vulnerability in the xmlhttprequest-ssl package for Node.js, affecting versions prior to 1.6.1. The flaw stems from the package's default behavior of disabling SSL certificate validation, effectively making all certificates trusted due to how Node.js's https.request function handles an undefined rejectUnauthorized property. This vulnerability carries a CVSS score of 9.4 (CRITICAL), indicating it can be exploited remotely with low attack complexity, leading to high impact on confidentiality and integrity, and low impact on availability. While there is no evidence of active exploitation (KEV list inactive) and no public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.1CPE matchmatch criteria | cpe:2.3:a:xmlhttprequest-ssl_project:xmlhttprequest-ssl:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.