First published: Thu Nov 16 2023(Updated: )
Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
Affected Software | Affected Version | How to fix |
---|---|---|
pip/httpie | <=3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is GHSA-8r96-8889-qg2x.
The title of this vulnerability is 'Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications.'
Attackers can exploit this vulnerability by performing a man-in-the-middle attack to eavesdrop on communications between the host and server.
HTTPie v3.2.2 is affected by this vulnerability.
To fix this vulnerability, update HTTPie to a version that includes the necessary SSL certificate validation.