Junglewise Threat Intelligence

CVE-2016-10667: selenium-portal insecure HTTP resource download

CVE-2016-10667 · Severity: info · CVSS 7.4 · Published 2019-02-18

Vendors: npm.

Executive brief

selenium-portal is a Node.js library that automates web browser testing. The package downloads executables over unencrypted HTTP connections, allowing attackers on the network to intercept and replace the executable with malicious code, leading to arbitrary code execution on systems using this library. No patch has been released since 2014.

Technical details

selenium-portal downloads executable resources over unencrypted HTTP instead of HTTPS, creating a man-in-the-middle (MITM) vulnerability (CWE-311: Missing Encryption of Sensitive Data). An attacker with network-level access (privileged network position, compromised ISP, or corporate network compromise) can intercept the HTTP response and replace the legitimate executable with a malicious binary, achieving arbitrary code execution on the target system. The vulnerability affects all versions up to 0.0.1-2, and no patch is available as the package has not been maintained since 2014. Exploitation requires the attacker to be on the same network or have network infrastructure access.

Affected products

  • npm selenium-portal 0.0.1-2 and earlier

Timeline

  • 2019-02-18: disclosed
  • other: CVE-2016-10667 assigned