Junglewise Threat Intelligence

CVE-2016-10623: macaca-chromedriver-zxa insecure download over HTTP

CVE-2016-10623 · Severity: info · CVSS 8.1 · Published 2019-02-18

Vendors: npm.

Executive brief

The macaca-chromedriver-zxa package, a tool used for automated web browser testing, downloads necessary executable files over an unencrypted HTTP connection. This allows an attacker positioned on the same network to intercept the download and replace the legitimate software with malicious code. If exploited, this could lead to a full compromise of the system where the package is being installed or updated.

Technical details

The macaca-chromedriver-zxa package (a Node.js wrapper for Selenium ChromeDriver) fails to use TLS/SSL when fetching binary resources during installation. Because the download occurs over plain HTTP, a network-positioned attacker (Man-in-the-Middle) can intercept the traffic and perform a binary replacement. By substituting the requested ChromeDriver executable with a malicious payload, the attacker can achieve arbitrary code execution on the victim's machine. This vulnerability affects all versions up to and including 0.1.9; users are advised to use the CHROMEDRIVER_CDNURL environment variable to specify a secure HTTPS source.

Affected products

  • macaca-js macaca-chromedriver-zxa <= 0.1.9

Timeline

  • 2016-10-09: disclosed: Vulnerability identified via Node Security Services
  • 2018-06-01: advisory: NVD published CVE-2016-10623
  • 2019-02-18: advisory: GitHub Advisory published

References