Skip to content

Security Fix for Resources Downloaded over Insecure Protocol - huntr.dev#2

Open
huntr-helper wants to merge 2 commits intoadamthesax:masterfrom
418sec:master
Open

Security Fix for Resources Downloaded over Insecure Protocol - huntr.dev#2
huntr-helper wants to merge 2 commits intoadamthesax:masterfrom
418sec:master

Conversation

@huntr-helper
Copy link

https://huntr.dev/users/Mik317 has fixed the Resources Downloaded over Insecure Protocol vulnerability 🔨. Mik317 has been awarded $25 for fixing the vulnerability through the huntr bug bounty program 💵. Think you could fix a vulnerability like this?

Get involved at https://huntr.dev/

Q | A
Version Affected | ALL
Bug Fix | YES
Original Pull Request | 418sec#1
Vulnerability README | https://github.com/418sec/huntr/blob/master/bounties/npm/node-wixtoolset/1/README.md

User Comments:

Bounty URL: https://www.huntr.dev/bounties/1-npm-node-wixtoolset

⚙️ Description *

A zip file is downloaded using a unencrypted and insecure channel, through http, being vulnerable against MITM.

💻 Technical Description *

I changed the http to https version and used the https library to request successfully the file 😄

🐛 Proof of Concept (PoC) *

No needed

🔥 Proof of Fix (PoF) *

No needed

👍 User Acceptance Testing (UAT)

All ok and working 👍

@ghost
Copy link

ghost commented Sep 3, 2020

Just to note: this fix assumes that the SSL configuration for the azure storage endpoint is valid and isn't using the default MS wildcard. The SSL config of static.wixtoolset.org may need its own SSL certificate - for example a free one from LetsEncrypt

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants