Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The custom HTTPS client disables certificate validation (CERT_NONE) and hostname checking, which removes TLS authentication and allows man-in-the-middle interception or tampering of API responses. Suppressing SNI further deviates from standard secure networking behavior and is not justified by the stated analytics use case, making remote data poisoning and misleading report generation feasible.
