Junglewise Threat Intelligence

CVE-2016-10628: selenium-wrapper insecure HTTP downloads

CVE-2016-10628 · Severity: low · CVSS 3 · Published 2019-02-18

Vendors: npm.

Executive brief

selenium-wrapper is a Node.js library that automates interaction with the Selenium WebDriver testing framework. The package downloads critical executables over unencrypted HTTP, allowing network attackers to intercept and replace those files with malicious code, leading to complete system compromise on the affected machine.

Technical details

selenium-wrapper fails to use HTTPS when downloading executables, instead retrieving them over plain HTTP. An attacker with network-layer access (man-in-the-middle position on the victim's network, ISP compromise, or privileged access to routing infrastructure) can intercept the download response and inject a malicious executable. Since the downloaded files are executed as part of the package's functionality, successful exploitation results in arbitrary code execution with the privileges of the user running Node.js. No patch is available; the recommended mitigation is to discontinue use of this package.

Affected products

  • npm selenium-wrapper <= 0.0.9

Timeline

  • 2019-02-18: disclosed: GitHub Advisory Database publication