OSV 1.4.0 · github-reviewed · 修改于 2023-09-07 04:06
发布时间
2018-07-24 23:40
GitHub 审查时间
2020-06-17 05:39
NVD 发布时间
—
源文件
advisories/github-reviewed/2018/07/GHSA-h8mc-42c3-r72p/GHSA-h8mc-42c3-r72p.json
Affected versions of hubl-server insecurely download dependencies over an unencrypted HTTP connection.
In scenarios where an attacker has a privileged network position, it is possible to intercept the responses and replace the dependencies with malicious ones, resulting in code execution on the system running hubl-server.
No patch is currently available for this vulnerability, and it has not seen any updates since 2015.
The best mitigation is currently to avoid using this package, using a different package if available.
Alternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised yo