Negligent Parachute Maintainers
Severity: high

Downloads Resources over HTTP

closurecompiler

Overview

Affected versions of closurecompiler insecurely download an executable over an unencrypted HTTP connection.

In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running closurecompiler.

Remediation

Update to version 1.6.1 or later.

Advisory timeline

  1. published

    Advisory published
    Dec 18th, 2016
  2. reported

    Nov 30th, 2016