Executive brief
Aerospike is a popular NoSQL database platform. Affected versions insecurely download executable files over unencrypted HTTP, allowing attackers on the network path to intercept and replace the executable with malicious code, leading to arbitrary code execution on systems running the database.
Technical details
The vulnerability is a missing encryption flaw (CWE-311) where Aerospike downloads executables over plaintext HTTP instead of HTTPS. An attacker with a privileged network position (e.g., on the same network, controlling a router, or performing DNS spoofing) can perform a man-in-the-middle attack to intercept the download and replace the executable with a malicious binary. This results in arbitrary code execution with the privileges of the Aerospike process. The attack requires network adjacency but no authentication or user interaction. The vulnerability affects all versions prior to 2.4.2, which includes the fix.
Affected products
- Aerospike aerospike < 2.4.2
Timeline
- 2019-02-18: disclosed
- 2016: patched: Version 2.4.2 released with fix