Machine-In-The-Middle in lix
High severity
GitHub Reviewed
Published
Apr 16, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 21, 2020
Reviewed
Apr 16, 2020
Published to the GitHub Advisory Database
Apr 16, 2020
Last updated
Feb 1, 2023
All versions of
lix
are vulnerable to Machine-In-The-Middle. The package accepts downloads withhttp
and followslocation
header redirects for package downloads. This allows for an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source.Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
References