Junglewise Threat Intelligence

CVE-2016-10536: engine.io-client insecure TLS certificate verification defaults

CVE-2016-10536 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

engine.io-client is a Node.js library used to establish real-time bidirectional communication channels between clients and servers. Versions before 1.6.9 disable TLS certificate verification by default, allowing attackers positioned on the network to intercept and modify communications through man-in-the-middle attacks. This could expose sensitive data transmitted over these connections, including authentication credentials and application data.

Technical details

The vulnerability is a TLS certificate verification bypass (CWE-300) in engine.io-client's default configuration. The vulnerable code set rejectUnauthorized to null when undefined, causing Node.js to disable certificate verification when the option was not explicitly provided. An attacker positioned on the network path between a client and server can intercept TLS connections and present their own certificate without triggering validation errors. High attack complexity indicates the attacker must be on the network path (adjacent or MITM position). No privileges or user interaction are required. The fix, implemented in commit 2c55b27, changed the default from null to true, ensuring certificates are validated by default. Patched version 1.6.9 and later include this fix; applications unable to upgrade should explicitly set rejectUnauthorized: true in all socket.io connection calls.

Affected products

  • Socket.io engine.io-client < 1.6.9

Timeline

  • 2019-02-18: disclosed
  • 2016: patched: Fix committed to repository; 1.6.9 released with patch

References