Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- This client disables TLS certificate verification by default by passing an unverified SSL context unless --verify-ssl is explicitly set. Because the script sends a Proxmox API token in the Authorization header, a machine-in-the-middle attacker could intercept credentials and API requests, enabling unauthorized access to cluster, VM, or container management functions.
