From c4155ea5987aba8f41a486bd66ba92ad94df4d6a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 13 Sep 2023 19:41:17 +0000 Subject: [PATCH] Publish GHSA-g95j-p8f6-pwh4 --- .../2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json b/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json index 8c49fc99a17..d3224d6b132 100644 --- a/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json +++ b/advisories/github-reviewed/2019/02/GHSA-g95j-p8f6-pwh4/GHSA-g95j-p8f6-pwh4.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g95j-p8f6-pwh4", - "modified": "2021-06-10T23:42:13Z", + "modified": "2023-09-13T19:39:29Z", "published": "2019-02-18T23:56:58Z", "aliases": [ "CVE-2016-10625" ], - "summary": "Downloads Resources over HTTP in headless-browser-lite", + "summary": "headless-browser-lite downloads Resources over HTTP", "details": "Affected versions of `headless-browser-lite` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `headless-browser-lite`.\n\n\n## Recommendation\n\nUpdate to version 2015.4.18-a or later.", "severity": [ { @@ -20,6 +20,11 @@ "ecosystem": "npm", "name": "headless-browser-lite" }, + "ecosystem_specific": { + "affected_functions": [ + "" + ] + }, "ranges": [ { "type": "ECOSYSTEM",