Executive brief
sauce-connect is a Node.js utility for connecting to Sauce Labs testing infrastructure. The package downloads an executable binary over unencrypted HTTP instead of HTTPS, allowing an attacker on the network (such as a compromised ISP or router) to intercept and replace the binary with malicious code, leading to arbitrary code execution on systems running the tool.
Technical details
The vulnerability is a missing encryption issue (CWE-311) where sauce-connect downloads an executable resource over unencrypted HTTP rather than HTTPS. An attacker with a privileged network position (man-in-the-middle on the same network, compromised ISP, or similar) can intercept the HTTP response and inject a malicious executable. The vulnerability requires network-adjacent or network positioning but no user interaction or elevated privileges. An attacker can achieve arbitrary code execution with the privileges of the user running sauce-connect. No patch has been released; the package has not been updated since 2013, and the maintainers recommend discontinuing use of this package.
Affected products
- sauce-connect sauce-connect ≤ 0.1.1
Timeline
- 2019-02-18: disclosed