diff --git a/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json b/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json index 8c49fc99a17..d3224d6b132 100644 --- a/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json +++ b/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g95j-p8f6-pwh4", - "modified": "2021-06-10T23:42:13Z", + "modified": "2023-09-13T19:39:29Z", "published": "2019-02-18T23:56:58Z", "aliases": [ "CVE-2016-10625" ], - "summary": "Downloads Resources over HTTP in headless-browser-lite", + "summary": "headless-browser-lite downloads Resources over HTTP", "details": "Affected versions of `headless-browser-lite` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `headless-browser-lite`.\n\n\n## Recommendation\n\nUpdate to version 2015.4.18-a or later.", "severity": [ { @@ -20,6 +20,11 @@ "ecosystem": "npm", "name": "headless-browser-lite" }, + "ecosystem_specific": { + "affected_functions": [ + "" + ] + }, "ranges": [ { "type": "ECOSYSTEM",