adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-1084 adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data.
Github GHSA Github GHSA GHSA-h2jv-5v3f-7m7j Downloads Resources over HTTP in adamvr-geoip-lite
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00166}

epss

{'score': 0.00172}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-09-16T22:30:52.903Z

Reserved: 2017-10-29T00:00:00

Link: CVE-2016-10680

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-29T20:29:01.970

Modified: 2024-11-21T02:44:30.013

Link: CVE-2016-10680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.