Junglewise Threat Intelligence

CVE-2016-10631: jvminstall downloads resources over HTTP

CVE-2016-10631 · Severity: info · CVSS 7.4 · Published 2019-02-18

Vendors: npm.

Executive brief

jvminstall is a Node.js package that installs Java Virtual Machine (JVM) components. The package insecurely downloads executable files over unencrypted HTTP connections, allowing attackers positioned on the network path to intercept and replace the executable with malicious code, leading to arbitrary code execution on affected systems.

Technical details

jvminstall contains an insecure download vulnerability (CWE-311: Missing Encryption of Sensitive Data) in which executable resources are downloaded over unencrypted HTTP rather than HTTPS. An attacker with network-level access (man-in-the-middle position) can intercept the HTTP response and inject a malicious executable. The vulnerability affects all versions up to and including 0.1.0, with no patch currently available. Exploitation requires the attacker to be positioned on the network path between the victim system and the download source, such as on a public WiFi network, or requires compromise of network infrastructure or ISP-level access.

Affected products

  • npm jvminstall <=0.1.0

Timeline

  • 2019-02-18: disclosed: Advisory published to GitHub Advisory Database
  • 2016: other: CVE-2016-10631 assigned (original discovery year)