adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1084 | adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data. |
Github GHSA |
GHSA-h2jv-5v3f-7m7j | Downloads Resources over HTTP in adamvr-geoip-lite |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://nodesecurity.io/advisories/283 |
|
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T22:30:52.903Z
Reserved: 2017-10-29T00:00:00
Link: CVE-2016-10680
No data.
Status : Modified
Published: 2018-05-29T20:29:01.970
Modified: 2024-11-21T02:44:30.013
Link: CVE-2016-10680
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA