CVE-2018-1000096

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
13/03/2018
Last modified:
11/04/2018

Description

brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tiny-json-http_project:tiny-json-http:*:*:*:*:*:*:*:* 1.0.0 (including) 7.0.0 (including)


References to Advisories, Solutions, and Tools