JS script Weather is using http to fetch information on geolocation based on zip and country codes.
Likelihood:
Not high
Impact:
If someone intercepted traffic, he/she will have api key for openweather. Also it would be possible to modify response and break dapp functionallity
Anyone able to intercept network traffic between the Chainlink Functions node and the OpenWeatherMap API endpoint (e.g., via a compromised network or malicious ISP) could read the API key and potentially modify the response.
Switch to https could help to reduce risk of exposing api key and/or intercepting request and modifying response
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.