Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Httpie | Httpie | 3.2.2 (including) | 3.2.2 (including) |
Httpie | Ubuntu | bionic | * |
Httpie | Ubuntu | lunar | * |
Httpie | Ubuntu | mantic | * |
Httpie | Ubuntu | trusty | * |
Httpie | Ubuntu | trusty/esm | * |
Httpie | Ubuntu | xenial | * |