Skip to content

Conversation

@stigtsp
Copy link

@stigtsp stigtsp commented Feb 28, 2023

The verify_SSL=>1 flag is missing from HTTP::Tiny, and could allow a network attacker to MITM https connections made by this distribution.

I'm not a Robinhood user, so unable to verify or test.

For more context see: https://hackeriet.github.io/cpan-http-tiny-overview/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant