3 ms·
You completely missed what this vulnerability is. It has nothing to do with intercepting another user's traffic. The checkout page in question actually uses SSL
by jaywalk 4y ago
You completely missed what this vulnerability is. It has nothing to do with intercepting another user's traffic. The checkout page in question actually uses SSL anyway, so it's not even possible absent some sort of MITM attack.
This has to do with API endpoints that exposed customer information and allowed password changes without checking that the request was coming from the customer. The customer didn't have to be logged in to the account, or even on the flight in the first place. If they had an account, it was exposed.
- Cupertino95014 4y agoQuite right. But as I said, "intercepting another user's traffic" would be an additional vulnerability, but not if you're on VPN. Maybe you could just admit that and end the argument. This doesn't require you to minimize the seriousness of the bug.