Skip to content
This repository was archived by the owner on Dec 19, 2023. It is now read-only.

[FIX] MITM issue#1

Merged
JamieSlome merged 1 commit into418sec:masterfrom
Mik317:master
Sep 10, 2020
Merged

[FIX] MITM issue#1
JamieSlome merged 1 commit into418sec:masterfrom
Mik317:master

Conversation

@Mik317
Copy link
Copy Markdown

@Mik317 Mik317 commented Sep 7, 2020

Bounty URL: https://www.huntr.dev/bounties/1-npm-openframe-image

⚙️ Description *

The openframe-image module was vulnerable against MITM and similar attacks since some resources were downloaded using a HTTP connection

💻 Technical Description *

I just changed the http links to https (certificates are OK on github.com 👍 )

🐛 Proof of Concept (PoC) *

Not needed

🔥 Proof of Fix (PoF) *

Using wireshark you're no more able to see the content of the downloaded files

👍 User Acceptance Testing (UAT)

All ok 👍

@JamieSlome JamieSlome merged commit 869c260 into 418sec:master Sep 10, 2020
@huntr-helper
Copy link
Copy Markdown

Congratulations Mik317 - your fix has been selected! 🎉

Thanks for being part of the community & helping secure the world's open source code.
If you have any questions, please respond in the comments section. Your bounty is on its way - keep hunting!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants