Description
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0277 | The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation. |
Github GHSA |
GHSA-h8mc-42c3-r72p | hubl-server downloads resources over HTTP |
References
| Link | Providers |
|---|---|
| https://nodesecurity.io/advisories/334 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-17T01:26:31.843Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16035
No data.
Status : Modified
Published: 2018-06-04T19:29:01.787
Modified: 2024-11-21T03:15:41.877
Link: CVE-2017-16035
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA