An issue was discovered in Listary through 6. Improper...
High severity
Unreviewed
Published
Dec 15, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 14, 2021
Published to the GitHub Advisory Database
Dec 15, 2021
Last updated
Feb 1, 2023
An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead to manipulation of update packages that can cause an installation of malicious content.
References