Description
lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled executable content in the postDownload field.
Remediation
References
https://www.npmjs.com/advisories/1306
Related Vulnerabilities
CVE-2012-6662 Vulnerability in npm package jquery-ui
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-jasper
CVE-2016-10593 Vulnerability in npm package ibapi
CVE-2021-29624 Vulnerability in npm package fastify-csrf
CVE-2020-2246 Vulnerability in maven package org.jenkins-ci.plugins:valgrind