CVE-2019-1000012 is a critical signing oracle vulnerability affecting Hex package manager versions 0.14.0 through 0.18.2. This flaw allows attackers to modify packages without detection, potentially leading to remote code execution on a victim's system if they fetch packages from a compromised mirror. With a CVSS score of 8.8 (High), it is easily exploitable over a network with low attack complexity, posing a significant risk of high impact to confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability has been addressed in Hex version 0.19.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.14.0, <= 0.18.2CPE matchmatch criteria | cpe:2.3:a:hex:hex:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.