Vulnerability Description
The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hubspot | Hubl-Server | <= 1.1.5 |
Related Weaknesses (CWE)
References
- https://nodesecurity.io/advisories/334Third Party Advisory
- https://nodesecurity.io/advisories/334Third Party Advisory
FAQ
What is CVE-2017-16035?
CVE-2017-16035 is a vulnerability with a CVSS score of 8.1 (HIGH). The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are do...
How severe is CVE-2017-16035?
CVE-2017-16035 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16035?
Check the references section above for vendor advisories and patch information. Affected products include: Hubspot Hubl-Server.