Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The code explicitly falls back to an SSL context with hostname checking disabled and certificate verification set to CERT_NONE, then uses that context for SEC HTTP requests. This permits man-in-the-middle interception and response tampering, which is especially risky because fetched financial data is trusted for output generation and reporting.
