Junglewise Threat Intelligence

CVE-2016-10619: pennyworth insecure resource download over HTTP

CVE-2016-10619 · Severity: info · CVSS 0 · Published 2019-02-18

Vendors: npm.

Executive brief

Pennyworth is a JavaScript utility library that downloads resources over insecure HTTP instead of encrypted HTTPS. An attacker with network access (such as on a compromised Wi-Fi network) can intercept, read, or modify these downloads, potentially injecting malicious code or stealing sensitive information. No patch is available; the primary mitigation is to avoid using the package or use it only on private networks.

Technical details

The vulnerability exists in pennyworth's resource-download mechanism, which uses HTTP instead of HTTPS for fetching external resources. This is a missing encryption / cleartext transmission issue (CWE-311). An attacker in a privileged network position (e.g., compromised Wi-Fi, ISP-level access, or network interception) can perform man-in-the-middle attacks to read or modify downloaded resources in transit. Depending on what resources are fetched and how they are used, this can lead to remote code execution, data exfiltration, or other compromise. No patch has been released for this vulnerability; all versions up to and including 1.0.1 are affected.

Affected products

  • npm pennyworth 0 to 1.0.1

Timeline

  • 2019-02-18: disclosed: Published to GitHub Advisory Database