Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sean1025 YMFE YApi 安全漏洞
Vulnerability Description
Sean1025 YMFE YApi是 Sean1025开源的一个应用软件。提供一个可视化接口管理平台 Sean1025 YMFE YApi v1.12.0版本存在安全漏洞,该漏洞源于证书验证不当,可能导致Axios请求的HTTPS代理配置中TLS/SSL证书验证被禁用。
CVSS Information
N/A
Vulnerability Type
N/A