{"id":"CVE-2016-10574","aliases":[],"url":"https://o3.security/vulnerability/CVE-2016-10574","summary":"Downloads Resources over HTTP in apk-parser3","details":"Affected versions of `apk-parser3` insecurely download an executable over an unencrypted HTTP connection. \n\nIn scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `apk-parser3`.\n\n\n## Recommendation\n\nUpdate to version 0.1.3 or greater.","published":"2020-09-01T16:06:49Z","modified":"2023-11-08T03:58:13.491516Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"apk-parser3","fixedVersion":"0.1.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10574"},{"type":"WEB","url":"https://www.npmjs.com/advisories/245"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:58:13.491516Z"}}