
Cloud Vulnerability DB
A community-led vulnerabilities database
ezseed-transmission, a module that provides shell bindings for Ezseed transmission, contains a vulnerability in versions 0.0.10 through 0.0.14 that was disclosed on July 29, 2016. The vulnerability is tracked as CVE-2016-1000224 and has been assigned a moderate severity CVSS score of 4.2 (GitHub Advisory).
The vulnerability stems from the application downloading and executing a script over an unsecured HTTP connection from http://stedolan.github.io/jq/download/linux64/jq without proper certificate validation. This implementation flaw is categorized under CWE-295 (Improper Certificate Validation) and CWE-300 (Channel Accessible by Non-Endpoint) (Snyk).
An attacker in a privileged network position could perform a Man-in-the-Middle (MITM) attack to intercept the script download and replace it with malicious code. This could lead to complete compromise of the system running ezseed-transmission (GitHub Advisory).
The vulnerability has an adjacent attack vector with high attack complexity, requiring no privileges or user interaction. The scope is unchanged, with low impacts on both confidentiality and integrity, and no impact on availability (GitHub Advisory).
Users should upgrade to version 0.0.15 or later, which contains the fix for this vulnerability. The fix was implemented through a commit that addresses the insecure download issue (Snyk).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."