Junglewise Threat Intelligence

CVE-2016-10588: NW.js insecure HTTP download of executable

CVE-2016-10588 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

NW.js is a framework for building desktop applications using web technologies. The package insecurely downloads runtime executables over plain HTTP, allowing an attacker in a privileged network position to intercept and replace the executable with malicious code, leading to complete system compromise during installation or updates.

Technical details

The vulnerability is a cleartext download issue (CWE-311) in the npm installer for NW.js. The install.js script constructs a download URL for the NW.js runtime executable using HTTP instead of HTTPS. An attacker with network-level access (man-in-the-middle position) can intercept the HTTP response and serve a malicious executable, achieving arbitrary code execution with the privileges of the user running npm install. The fix, released in version 0.23.6-1, changes the default download URL base from http://dl.nwjs.io to https://dl.nwjs.io. All versions prior to 0.23.6-1 are affected.

Affected products

  • NW.js nw before 0.23.6-1

Timeline

  • 2019-02-18: disclosed: GHSA advisory published
  • 2016: patched: Fix released in version 0.23.6-1 via commit adb4df1

References