PT-2020-12332 · Lix · Lix
Published
2020-03-21
·
Updated
2021-07-21
·
CVE-2020-10800
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
lix versions 15.8.7 and earlier
Description
The issue allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream. This is done by associating the Location header with attacker-controlled executable content in the postDownload field. The package accepts downloads with
http and follows location header redirects for package downloads, allowing an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source.Recommendations
For versions 15.8.7 and earlier, consider using an alternative package until a fix is made available. As a temporary workaround, consider restricting the use of the
http protocol for package downloads to minimize the risk of exploitation. Avoid using the location header redirects for package downloads until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lix