Junglewise Threat Intelligence

CVE-2016-10676: rs-brightcove remote code execution via insecure HTTP download

CVE-2016-10676 · Severity: info · CVSS 8.1 · Published 2019-02-18

Vendors: npm.

Executive brief

The rs-brightcove library, which is used to interact with Brightcove's video APIs, downloads executable resources over an unencrypted connection. This allows an attacker who can monitor or control your network traffic (such as on a public Wi-Fi or a compromised ISP) to replace the legitimate file with a malicious one. If exploited, this could allow the attacker to take full control of the system running the software.

Technical details

The rs-brightcove package (versions 0.0.2 and earlier) fails to use TLS/SSL when fetching executable source files, relying instead on plain HTTP. This vulnerability (CWE-311) allows a network-positioned attacker to perform a Man-in-the-Middle (MitM) attack. By intercepting the HTTP request, the attacker can inject a malicious payload in place of the intended executable, leading to Remote Code Execution (RCE) on the host machine. No patch is currently available; users are advised to migrate to alternative packages or ensure installation occurs only on trusted, secure networks.

Affected products

  • rs-brightcove project rs-brightcove <= 0.0.2

Timeline

  • 2016-10-09: disclosed: Vulnerability identified (based on CVE year)
  • 2018-06-04: advisory: NVD published the CVE record
  • 2019-02-18: advisory: GitHub Advisory published

References