The boost ASIO wrapper in net/asio.cpp in Pichi before 1.3.0 lacks TLS hostname verification.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://github.com/pichi-router/pichi/commit/4698664233bc324f26658d2b041bfe6ea022c573 | third party advisory patch |
https://github.com/pichi-router/pichi/releases/tag/1.3.0 | third party advisory release notes |