GHSA-7h42-5vj2-cq39
Dashboard / Vulnerabilities / GHSA-7h42-5vj2-cq39
Summary: tiny-json-http missing SSL certificate validation
Details: brianleroux tiny-json-http version all versions since commit [9b8e74a232bba4701844e07bcba794173b0238a8](https://github.com/brianleroux/tiny-json-http/commit/9b8e74a232bba4701844e07bcba794173b0238a8) (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the user to man-in-the-middle attacks.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000096, https://github.com/brianleroux/tiny-json-http/pull/15, https://github.com/brianleroux/tiny-json-http/commit/3c1e36d8bef3ef5fd8e4447f816d5ffe2bfc3190, https://github.com/advisories/GHSA-7h42-5vj2-cq39, https://github.com/brianleroux/tiny-json-http
Affected packages
Package
Name: tiny-json-http
Purl: pkg:npm/tiny-json-http
Affected ranges
Type: SEMVER
Events:
