Insecure Defaults Leads to Potential MITM in ezseed-transmission
Moderate severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Jan 9, 2023
Affected versions of
ezseed-transmission
download and run a script over an HTTP connection.An attacker in a privileged network position could launch a Man-in-the-Middle attack and intercept the script, replacing it with malicious code, completely compromising the system running
ezseed-transmission
.Recommendation
Update to version 0.0.15 or later.
References