Impact
An attacker with the ability to actively intercept network traffic would be able to use a specifically-crafted certificate to fool Pluto into trusting it to be the intended remote for the TLS session.
This results in the HTTP library and socket.starttls providing less transport integrity than expected. The HTTP library in WASM builds is not affected.
Impact
An attacker with the ability to actively intercept network traffic would be able to use a specifically-crafted certificate to fool Pluto into trusting it to be the intended remote for the TLS session.
This results in the HTTP library and socket.starttls providing less transport integrity than expected. The HTTP library in WASM builds is not affected.