The application fails to prevent users from connecting to...
Moderate severity
Unreviewed
Published
Nov 23, 2022
to the GitHub Advisory Database
•
Updated Jul 7, 2023
Description
Published by the National Vulnerability Database
Nov 23, 2022
Published to the GitHub Advisory Database
Nov 23, 2022
Last updated
Jul 7, 2023
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
References