Package Registry Verification Vulnerability in Hex Package Manager
CVE-2019-1000013
8.8HIGH
What is CVE-2019-1000013?
The Hex Package Manager, specifically version 0.3.0 and earlier of hex_core, is vulnerable to a signing oracle issue in its package registry verification process. This vulnerability allows for undetected modifications to packages, which could lead to the execution of malicious code. Attackers can exploit this by tricking users into fetching compromised packages from malicious mirrors. The issue has been resolved in version 0.4.0, underscoring the importance of using updated software to maintain security.