All versions of lix
are vulnerable to Machine-In-The-Middle. The package accepts downloads with http
and follows location
header redirects for package downloads. This allows for an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source.
No fix is currently available. Consider using an alternative package until a fix is made available.
{ "nvd_published_at": "2020-03-21T15:15:00Z", "github_reviewed_at": "2020-04-16T03:10:39Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-544", "CWE-639" ] }