Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Httpie | Httpie | 3.2.2 (including) | 3.2.2 (including) |
| Httpie | Ubuntu | bionic | * |
| Httpie | Ubuntu | focal | * |
| Httpie | Ubuntu | lunar | * |
| Httpie | Ubuntu | mantic | * |
| Httpie | Ubuntu | oracular | * |
| Httpie | Ubuntu | trusty | * |
| Httpie | Ubuntu | trusty/esm | * |
| Httpie | Ubuntu | xenial | * |