An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting rejectUnauthorized: false in TLS socket options
The product does not validate, or incorrectly validates, a certificate.