Executive brief
The scala-bin package, a binary wrapper for the Scala programming language, downloads its core components over an unencrypted HTTP connection. This allows an attacker who can monitor or control your network traffic (such as on a public Wi-Fi or a compromised corporate network) to intercept the download and replace the legitimate software with malicious code. If exploited, this could lead to a full takeover of the system where the package is being installed or updated.
Technical details
The scala-bin package (up to version 0.3.3) fails to use TLS/SSL when fetching binary resources during installation or execution. This vulnerability is classified as a missing encryption issue (CWE-311). An attacker with a privileged network position (Man-in-the-Middle) can intercept the cleartext HTTP traffic and inject a malicious payload in place of the expected Scala binary. This results in arbitrary code execution on the host system. As of the latest advisory, no patch is available, and users are advised to avoid the package or ensure installation occurs only on trusted, secure networks.
Affected products
- scala-bin project scala-bin <= 0.3.3
Timeline
- 2016-10-09: disclosed: Vulnerability identified via HackerOne/Node Security Project
- 2018-05-29: advisory: NVD published CVE-2016-10627
- 2019-02-18: advisory: GitHub Advisory GHSA-3vv5-42wr-m32g published