Junglewise Threat Intelligence

CVE-2016-1000238: node-krb5 KDC spoofing due to insufficient validation

CVE-2016-1000238 · Severity: info · Published 2020-09-01

Vendors: npm.

Executive brief

node-krb5 is a Node.js library for Kerberos authentication, commonly used in enterprise environments to authenticate users against Active Directory and other directory services. A failure to validate the KDC server allows a network-positioned attacker to intercept authentication requests and impersonate legitimate users, potentially gaining unauthorized access to protected systems and data. The maintainers have not addressed this issue since 2015, and users are advised to migrate to an actively maintained alternative.

Technical details

The vulnerability is a KDC spoofing attack caused by insufficient validation of the Key Distribution Center before processing authentication credentials. An attacker with network access (able to intercept or redirect KDC communications) can respond to authentication requests with a fraudulent KDC response, allowing them to impersonate any valid user without knowledge of their password. The attack vector is network-based and requires no user interaction, though successful exploitation depends on the attacker's ability to manipulate network traffic (e.g., via ARP spoofing, DNS hijacking, or being on the same network segment). No patch is available as the project appears abandoned since the issue was reported in 2015; mitigation requires switching to an actively maintained Kerberos library.

Affected products

  • node-krb5 node-krb5 all versions

Timeline

  • 2015: disclosed: Issue reported on GitHub
  • 2020-09-01: advisory: Published in GitHub Advisory Database
  • 2023-11-08: other: Advisory last modified; no fix available

References