Via HackerOne. A researcher correctly reports that our install scripts use HTTP, not HTTPS, to fetch resources and execute them as root, which is a potentially significant vulnerability.
Instead, use HTTPS.
Differential D16958
Use HTTPS, not HTTP, in install scripts epriestley on Nov 29 2016, 1:29 PM. Authored by Tags None Referenced Files
Subscribers None
Details
Via HackerOne. A researcher correctly reports that our install scripts use HTTP, not HTTPS, to fetch resources and execute them as root, which is a potentially significant vulnerability. Instead, use HTTPS. Verified that these URIs function correctly over HTTPS.
Diff Detail
|