Vulnerability Description
lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled executable content in the postDownload field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lix Project | Lix | <= 15.8.7 |
References
- https://www.npmjs.com/advisories/1306Third Party Advisory
- https://www.npmjs.com/advisories/1306Third Party Advisory
FAQ
What is CVE-2020-10800?
CVE-2020-10800 is a vulnerability with a CVSS score of 8.1 (HIGH). lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled execu...
How severe is CVE-2020-10800?
CVE-2020-10800 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10800?
Check the references section above for vendor advisories and patch information. Affected products include: Lix Project Lix.