Description
lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled executable content in the postDownload field.
Remediation
References
https://www.npmjs.com/advisories/1306
Related Vulnerabilities
CVE-2020-6950 Vulnerability in maven package org.glassfish:jakarta.faces
CVE-2018-1288 Vulnerability in maven package org.apache.kafka:kafka_2.10
CVE-2020-10672 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-2293 Vulnerability in maven package org.jenkins-ci.plugins:persona