NA

CVE-2022-32210

Published: 14/07/2022 Updated: 25/07/2022
CVSS v3 Base Score: 6.5 | Impact Score: 4.2 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nodejs undici