PT-2018-6069 · Ikst · Ikst
Published
2018-06-04
·
Updated
2019-10-09
·
CVE-2017-16041
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
ikst versions prior to 1.1.2
Description:
The issue allows for insecure downloading of resources over HTTP, making it susceptible to man-in-the-middle (MITM) attacks. In scenarios where an attacker has a privileged network position, they can modify or read such resources at will. The impact can range from reading sensitive information to remote code execution, depending on the package's behavior.
Recommendations:
Upgrade to version 1.1.2 or greater.
Fix
Cleartext Transmission of Sensitive Information
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ikst