Junglewise Threat Intelligence

CVE-2016-10643: jstestdriver insecure HTTP resource download

CVE-2016-10643 · Severity: info · Published 2018-08-15

Vendors: npm.

Executive brief

jstestdriver is a JavaScript testing tool that downloads executable resources over unencrypted HTTP connections. An attacker with network access can intercept and replace the downloaded executable with malicious code, leading to arbitrary code execution on any system running the tool.

Technical details

The vulnerability is a missing encryption issue (CWE-311) where jstestdriver downloads executables over HTTP instead of HTTPS, making the traffic vulnerable to man-in-the-middle (MITM) attacks. An attacker with a privileged network position (on the same network, controlling network infrastructure, or with ISP-level access) can intercept the HTTP response and inject a malicious executable. This results in arbitrary code execution with the privileges of the user running jstestdriver. No patch has been released; the package has not been updated since 2011, and the advisory recommends either discontinuing use or restricting deployment to private networks with access controls.

Affected products

  • jstestdriver jstestdriver all versions

Timeline

  • 2018-08-15: disclosed
  • other: No updates since 2011; no patch available