Junglewise Threat Intelligence

CVE-2016-10599: sauce-connect insecure HTTP download of executable

CVE-2016-10599 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

sauce-connect is a Node.js utility for connecting to Sauce Labs testing infrastructure. The package downloads an executable binary over unencrypted HTTP instead of HTTPS, allowing an attacker on the network (such as a compromised ISP or router) to intercept and replace the binary with malicious code, leading to arbitrary code execution on systems running the tool.

Technical details

The vulnerability is a missing encryption issue (CWE-311) where sauce-connect downloads an executable resource over unencrypted HTTP rather than HTTPS. An attacker with a privileged network position (man-in-the-middle on the same network, compromised ISP, or similar) can intercept the HTTP response and inject a malicious executable. The vulnerability requires network-adjacent or network positioning but no user interaction or elevated privileges. An attacker can achieve arbitrary code execution with the privileges of the user running sauce-connect. No patch has been released; the package has not been updated since 2013, and the maintainers recommend discontinuing use of this package.

Affected products

  • sauce-connect sauce-connect ≤ 0.1.1

Timeline

  • 2019-02-18: disclosed