{"id":"GHSA-h8mc-42c3-r72p","summary":"hubl-server downloads resources over HTTP","details":"Affected versions of `hubl-server` insecurely download dependencies over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the responses and replace the dependencies with malicious ones, resulting in code execution on the system running `hubl-server`.\n\n\n## Recommendation\n\nNo patch is currently available for this vulnerability, and it has not seen any updates since 2015.\n\nThe best mitigation is currently to avoid using this package, using a different package if available. \n\nAlternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised yo","aliases":["CVE-2017-16035"],"modified":"2023-11-08T03:59:00.802973Z","published":"2018-07-24T15:40:47Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-311"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:39:31Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16035"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h8mc-42c3-r72p"},{"type":"WEB","url":"https://www.npmjs.com/advisories/334"}],"affected":[{"package":{"name":"hubl-server","ecosystem":"npm","purl":"pkg:npm/hubl-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-h8mc-42c3-r72p/GHSA-h8mc-42c3-r72p.json"}}],"schema_version":"1.9.0"}