Man-in-the-Middle (MitM) Affecting package, versions *

  • Attack Complexity


  • snyk-id


  • published

    17 Oct 2017

  • disclosed

    3 Oct 2017

  • credit

    Eric Holmes

How to fix?

A fix was pushed into the master branch but not yet published.

Overview is a control layer on top of Amazon EC2 Container Service (ECS) that provides a Heroku like workflow.

Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). The X-Forwarded-For header was not blacklisted and it was possible to spoof ip addresses.