Логотип exploitDog
bind:CVE-2017-16035
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-16035

Количество 2

Количество 2

nvd логотип

CVE-2017-16035

больше 7 лет назад

The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-h8mc-42c3-r72p

больше 7 лет назад

hubl-server downloads resources over HTTP

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-16035

The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.

CVSS3: 8.1
0%
Низкий
больше 7 лет назад
github логотип
GHSA-h8mc-42c3-r72p

hubl-server downloads resources over HTTP

0%
Низкий
больше 7 лет назад

Уязвимостей на страницу