The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.
References
Link | Resource |
---|---|
https://nodesecurity.io/advisories/334 | Third Party Advisory |
Configurations
Information
Published : 2018-06-04 12:29
Updated : 2019-10-09 16:24
NVD link : CVE-2017-16035
Mitre link : CVE-2017-16035
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
hubspot
- hubl-server