QID 980931

QID 980931: Nodejs (npm) Security Update for lix (GHSA-q8xg-8xwf-m598)

All versions of `lix` are vulnerable to Machine-In-The-Middle. The package accepts downloads with `http` and follows `location` header redirects for package downloads. This allows for an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source.


## Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-q8xg-8xwf-m598 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980931

    Software Advisories
    Advisory ID Software Component Link
    GHSA-q8xg-8xwf-m598 lix URL Logo github.com/advisories/GHSA-q8xg-8xwf-m598