Junglewise Threat Intelligence

CVE-2016-10576: fuseki insecure resource download via HTTP

CVE-2016-10576 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

The fuseki package, a server wrapper and management API, downloads executable resources over an unencrypted HTTP connection. An attacker positioned on the same network or between the user and the server could intercept this download and replace it with malicious software. This could allow the attacker to take full control of the system running the software, leading to data theft or service disruption.

Technical details

The fuseki server wrapper and management API (npm package 'fuseki') fails to use encryption (HTTPS) when downloading binary resources. This vulnerability is classified as CWE-311 (Missing Encryption of Sensitive Data). An attacker with a privileged network position (Man-in-the-Middle) can intercept the unencrypted HTTP traffic and replace the requested binary with a malicious payload. Successful exploitation results in remote code execution (RCE) on the host system. The issue is fixed in version 1.0.1, which transitions these downloads to secure channels.

Affected products

  • fuseki project fuseki < 1.0.1

Timeline

  • 2016-10-05: disclosed: Date based on CVE ID year and original advisory reports
  • 2018-06-01: advisory: NVD published date
  • 2019-02-18: advisory: GitHub Advisory Database publication

References