Today Node.js announced and released a security fix for CVE-2021-22939 , along with two other high severity issues. They’ve rated this vulnerability as ‘low severity’, but I think it’s worth a closer look, as (imo) this really understates the risk here, and the potentially widespread impact. In practice, this poses a risk to anybody making TLS connections from Node.js, e.g.
HTTPS certificate non-validation vulnerability in Node.js
calendar_today
August 11, 2021
domain
http-toolkit