Junglewise Threat Intelligence

CVE-2016-10552: Infragistics igniteui insecure resource download over HTTP

CVE-2016-10552 · Severity: info · CVSS 7.4 · Published 2019-02-18

Vendors: npm.

Executive brief

The igniteui library, used for building web user interfaces, downloads essential JavaScript and CSS files over an unencrypted HTTP connection. This allows an attacker on the same network to intercept or modify the code being sent to a user's browser. Such an attack could lead to the theft of sensitive information or the execution of malicious scripts on the user's machine.

Technical details

The igniteui package (versions 0.0.5 and earlier) fails to use TLS/SSL when fetching remote JavaScript and CSS dependencies, relying instead on plaintext HTTP. This vulnerability (CWE-311) allows a network-positioned attacker to perform a Man-in-the-Middle (MitM) attack to intercept or inject malicious code into the application's frontend. While the NVD provides a CVSS score of 7.4, the GitHub Advisory Database classifies the severity as Low. The original 'igniteui' package has been deprecated; users are advised to migrate to the 'ignite-ui' package which addresses these security concerns.

Affected products

  • Infragistics igniteui <= 0.0.5

Timeline

  • 2016-10-05: disclosed: Vulnerability identified via Node Security Services
  • 2018-05-31: advisory: NVD published CVE-2016-10552
  • 2019-02-18: advisory: GitHub Advisory published GHSA-2r5h-gh4x-8hp9

References