Back

HIGH

v8: fibjs runtime downloads binary resources over HTTP

Published Jun 1, 2018

Description

fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Affected products

Remediation

Red Hat statement

The fibjs NPM module is not used in any Red Hat products.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jun 1, 2018
Updated Sep 16, 2024
Reserved Oct 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 1, 2017
GHSA-6P48-XFJ3-JW67