All versions of lix are vulnerable to Machine-In-The-Middle. The package accepts downloads with http and follows location header redirects for package downloads. This allows for an attacker in a privileged network position to intercept a lix package installation and redirect the download to a malicious source.
No fix is currently available. Consider using an alternative package until a fix is made available.
{
"github_reviewed": true,
"github_reviewed_at": "2020-04-16T03:10:39Z",
"nvd_published_at": "2020-03-21T15:15:00Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-544",
"CWE-639"
]
}