CVE-2016-10610: High severity Unicode Unicode-json Node.js vulnerability
Published Jun 1, 2018
·Updated
unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
Affected Software
1 affected component
Unicode Unicode-json Node.js<2.0.0
Event History
Jun 1, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2016-10610?
CVE-2016-10610 is a vulnerability in unicode-json before 2.0.0 that allows for MITM attacks due to downloading data resources over HTTP.
2
What software is affected by CVE-2016-10610?
Unicode Unicode-json version up to but excluding 2.0.0 running on Node.js is affected by CVE-2016-10610.
3
What is the severity of CVE-2016-10610?
The severity of CVE-2016-10610 is high, with a CVSS score of 8.1.
4
How can I fix CVE-2016-10610?
To fix CVE-2016-10610, upgrade to unicode-json version 2.0.0 or later.
5
Where can I find more information about CVE-2016-10610?
You can find more information about CVE-2016-10610 at this reference: https://nodesecurity.io/advisories/206