logo

CVE-2020-10800 lix

Package

Manager: npm
Name: lix
Vulnerable Version: >=0 <=15.11.4

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.0041 pctl0.60512

Details

Machine-In-The-Middle in lix All versions of `lix` are vulnerable to Machine-In-The-Middle. The package accepts downloads with `http` and follows `location` header redirects for package downloads. This allows for an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source. ## Recommendation No fix is currently available. Consider using an alternative package until a fix is made available.

Metadata

Created: 2020-04-16T03:14:59Z
Modified: 2021-09-16T20:39:54Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-q8xg-8xwf-m598/GHSA-q8xg-8xwf-m598.json
CWE IDs: ["CWE-544", "CWE-639"]
Alternative ID: GHSA-q8xg-8xwf-m598
Finding: F039
Auto approve: 1