Junglewise Threat Intelligence

CVE-2016-10644: slimerjs-edge insecure executable download over HTTP

CVE-2016-10644 · Severity: low · CVSS 3.1 · Published 2018-08-15

Vendors: npm.

Executive brief

slimerjs-edge is a Node.js package that downloads executable files needed for its operation. The package insecurely downloads these files over unencrypted HTTP connections, allowing attackers positioned on the network path (such as on a public Wi-Fi network or compromised ISP) to intercept and replace the executable with malicious code. This results in arbitrary code execution on the system running slimerjs-edge.

Technical details

The vulnerability exists in slimerjs-edge's package installation process, which fetches a required executable over HTTP rather than HTTPS. This is a missing encryption issue (CWE-311) affecting the integrity and authenticity of downloaded resources. An attacker positioned on the network path (such as on a shared network, public Wi-Fi, or via BGP hijacking) can perform a man-in-the-middle attack to intercept the HTTP response and inject a malicious executable without requiring authentication or user interaction. Upon installation, the compromised executable will be executed with the privileges of the user running npm install, granting the attacker full code execution. No patch has been released for this vulnerability; the GitHub advisory recommends avoiding the package entirely or limiting its installation to private networks only.

Affected products

  • slimerjs-edge contributors slimerjs-edge all versions

Timeline

  • 2018-08-15: disclosed: Published to GitHub Advisory Database
  • 2016: other: CVE-2016-10644 assigned (CVE date indicates earlier discovery)

References