{"id":"GHSA-p788-rj37-357w","summary":"Insecure Defaults Leads to Potential MITM in ezseed-transmission","details":"Affected versions of `ezseed-transmission` download and run a script over an HTTP connection.\n\nAn attacker in a privileged network position could launch a Man-in-the-Middle attack and intercept the script, replacing it with malicious code, completely compromising the system running `ezseed-transmission`.\n\n\n\n## Recommendation\n\nUpdate to version 0.0.15 or later.","aliases":["CVE-2016-1000224"],"modified":"2023-11-08T03:58:07.413368Z","published":"2020-09-01T15:26:35Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:11:16Z","nvd_published_at":null,"cwe_ids":["CWE-295","CWE-300"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-1000224"},{"type":"WEB","url":"https://snyk.io/vuln/npm:ezseed-transmission:20160729"},{"type":"WEB","url":"https://www.npmjs.com/advisories/114"}],"affected":[{"package":{"name":"ezseed-transmission","ecosystem":"npm","purl":"pkg:npm/ezseed-transmission"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.10"},{"fixed":"0.0.15"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.0.14","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-p788-rj37-357w/GHSA-p788-rj37-357w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}