Executive brief
selenium-portal is a Node.js library that automates web browser testing. The package downloads executables over unencrypted HTTP connections, allowing attackers on the network to intercept and replace the executable with malicious code, leading to arbitrary code execution on systems using this library. No patch has been released since 2014.
Technical details
selenium-portal downloads executable resources over unencrypted HTTP instead of HTTPS, creating a man-in-the-middle (MITM) vulnerability (CWE-311: Missing Encryption of Sensitive Data). An attacker with network-level access (privileged network position, compromised ISP, or corporate network compromise) can intercept the HTTP response and replace the legitimate executable with a malicious binary, achieving arbitrary code execution on the target system. The vulnerability affects all versions up to 0.0.1-2, and no patch is available as the package has not been maintained since 2014. Exploitation requires the attacker to be on the same network or have network infrastructure access.
Affected products
- npm selenium-portal 0.0.1-2 and earlier
Timeline
- 2019-02-18: disclosed
- other: CVE-2016-10667 assigned