Junglewise Threat Intelligence

CVE-2016-10669: soci insecure HTTP download of executable

CVE-2016-10669 · Severity: info · CVSS 7.5 · Published 2019-02-18

Vendors: npm.

Executive brief

soci is a Node.js package that downloads executable files during installation. The package downloads these executables over unencrypted HTTP rather than secure HTTPS, allowing attackers on the network path to intercept and replace the executable with malicious code, leading to code execution on the installing system.

Technical details

The vulnerability is a missing encryption of sensitive data (CWE-311) issue where soci downloads an executable binary over an unencrypted HTTP connection rather than HTTPS. An attacker with a privileged network position (man-in-the-middle capability) can intercept the HTTP response and inject a malicious executable to achieve remote code execution during package installation. The attack requires network-level access but no authentication. No patch has been published; the recommendation is to avoid the package entirely or limit installation to private networks where network compromise is less likely.

Affected products

  • npm soci <=3.2.2

Timeline

  • 2019-02-18: disclosed
  • 2020-06-16: advisory: GitHub Advisory Database review date