GHSA-q8xg-8xwf-m598

Suggest an improvement
Source
https://github.com/advisories/GHSA-q8xg-8xwf-m598
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-q8xg-8xwf-m598/GHSA-q8xg-8xwf-m598.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-q8xg-8xwf-m598
Aliases
  • CVE-2020-10800
Published
2020-04-16T03:14:59Z
Modified
2023-11-01T04:51:27.312379Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Machine-In-The-Middle in lix
Details

All versions of lix are vulnerable to Machine-In-The-Middle. The package accepts downloads with http and follows location header redirects for package downloads. This allows for an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Database specific
{
    "nvd_published_at": "2020-03-21T15:15:00Z",
    "github_reviewed_at": "2020-04-16T03:10:39Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-544",
        "CWE-639"
    ]
}
References

Affected packages

npm / lix

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
15.11.4