Executive brief
The rs-brightcove library, which is used to interact with Brightcove's video APIs, downloads executable resources over an unencrypted connection. This allows an attacker who can monitor or control your network traffic (such as on a public Wi-Fi or a compromised ISP) to replace the legitimate file with a malicious one. If exploited, this could allow the attacker to take full control of the system running the software.
Technical details
The rs-brightcove package (versions 0.0.2 and earlier) fails to use TLS/SSL when fetching executable source files, relying instead on plain HTTP. This vulnerability (CWE-311) allows a network-positioned attacker to perform a Man-in-the-Middle (MitM) attack. By intercepting the HTTP request, the attacker can inject a malicious payload in place of the intended executable, leading to Remote Code Execution (RCE) on the host machine. No patch is currently available; users are advised to migrate to alternative packages or ensure installation occurs only on trusted, secure networks.
Affected products
- rs-brightcove project rs-brightcove <= 0.0.2
Timeline
- 2016-10-09: disclosed: Vulnerability identified (based on CVE year)
- 2018-06-04: advisory: NVD published the CVE record
- 2019-02-18: advisory: GitHub Advisory published