VDB
Sign up
HIGH7.4

GHSA-663h-2vr3-ghrj

yapi disables TLS/SSL certificate validation via rejectUnauthorized: false in Axios HTTPS agent

Details

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/yapi-vendor
Introduced in: 0

No fixed version published yet for yapi-vendor (npm). Pin to a known-safe version or switch to an alternative.

References