Serverpod client accepts any certificate
Description
Published by the National Vulnerability Database
Mar 27, 2024
Published to the GitHub Advisory Database
Mar 28, 2024
Reviewed
Mar 28, 2024
Last updated
Mar 28, 2024
This bug bypassed the validation of TSL certificates on all none web HTTP clients in the
serverpod_client
package. Making them susceptible to a man in the middle attack against encrypted traffic between the client device and the server.An attacker would need to be able to intercept the traffic and highjack the connection to the server for this vulnerability to be used.
Impact
All versions of
serverpod_client
pre1.2.6
Patches
Upgrading to version
1.2.6
resolves this issue.References