Junglewise Threat Intelligence

CVE-2016-10563: go-ipfs-dep insecure HTTP resource downloads

CVE-2016-10563 · Severity: info · CVSS 0 · Published 2019-02-18

Vendors: npm.

Executive brief

go-ipfs-dep is a Node.js package that downloads IPFS (InterPlanetary File System) binaries as part of its installation process. The package downloads these resources over unencrypted HTTP instead of HTTPS, allowing attackers on the network path to intercept and modify the downloaded binaries. This could lead to arbitrary code execution during installation if an attacker can position themselves between the user and the download server.

Technical details

The vulnerability is a cleartext protocol issue (CWE-311) where go-ipfs-dep downloads binary resources over HTTP rather than HTTPS. An attacker with a privileged network position (man-in-the-middle) can intercept these downloads and inject malicious code into the binaries before they are installed. The attack requires no authentication and is network-adjacent (same network segment or compromised routing infrastructure). The impact ranges from information disclosure of downloaded resources to remote code execution through binary manipulation. The fix is to update to version 0.4.4 or later, which switches downloads to HTTPS as evidenced by the referenced pull request.

Affected products

  • IPFS go-ipfs-dep before 0.4.4

Timeline

  • 2019-02-18: disclosed: Advisory published
  • 2016-10-29: patched: Fix merged in PR #12 to use HTTPS
  • 2016: other: CVE-2016-10563 assigned

References