adamvr-geoip-lite is a light weight native JavaScript implementation of GeoIP API from MaxMind adamvr-geoip-lite downloads geoip resources over HTTP, which leaves it vulnerable to MITM attacks. This impacts the integrity and availability of this geoip data that may alter the decisions made by an application using this data.
References
Link Resource
https://nodesecurity.io/advisories/283 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2018-04-26T00:00:00

Updated: 2018-05-29T19:57:02

Reserved: 2017-10-29T00:00:00


Link: CVE-2016-10680

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-05-29T20:29:01.970

Modified: 2019-10-09T23:17:00.623


Link: CVE-2016-10680

JSON object: View

cve-icon Redhat Information

No data.