Weather Witness

First Flight #40
Beginner FriendlyFoundrySolidityNFT
100 EXP
View results
Submission Details
Severity: low
Valid

Insecure HTTP Request

Insecure HTTP Request
Apply to :
url: "http://api.openweathermap.org/geo/1.0/zip"

Using HTTP instead of HTTPS for the geocoding API
Could allow man-in-the-middle attacks
Data could be intercepted or modified

Updates

Appeal created

bube Lead Judge 5 days ago
Submission Judgement Published
Validated
Assigned finding tags:

Use of `http` instead of `https` for getting geo location

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.