Skip to content

Conversation

@stigtsp
Copy link

@stigtsp stigtsp commented Feb 28, 2023

The verify_SSL=>1 flag is missing from HTTP::Tiny, and could allow a network attacker to MITM https connections made by this distribution.

Maybe Paws doesn't need certificate verification like AWS::Lambda if that's the case I'm sorry for the false alarm. Also, I'm not an AWS customer so haven't been able to test this change.

For more context see: https://hackeriet.github.io/cpan-http-tiny-overview/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant