Ayms node-Tor
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*
- master
A vulnerability exists in Ayms node-To master branch, where the application improperly validates TLS/SSL certificates. This is achieved by setting 'rejectUnauthorized' to false in the TLS socket options, which can allow man-in-the-middle attackers to spoof servers and intercept sensitive data.
Exploitation of this vulnerability could lead to man-in-the-middle attacks, allowing interception of sensitive data and server spoofing.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.