—
GO-2021-0083
Improper certificate validation in github.com/hybridgroup/gobot
Quick fix
GO-2021-0083 — github.com/hybridgroup/gobot: upgrade to the fixed version with the command below.
go get github.com/hybridgroup/gobot@v1.12.1-0.20190521122906-c1aa4f867846Details
TLS certificate verification is skipped when connecting to a MQTT server. This allows an attacker who can MITM the connection to read, or forge, messages passed between the client and server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hybridgroup/gobot
Introduced in:
0Fixed in: 1.12.1-0.20190521122906-c1aa4f867846Fix
go get github.com/hybridgroup/gobot@v1.12.1-0.20190521122906-c1aa4f867846