Executive brief
fis-sass-all is a Node.js package that downloads executable files needed for Sass preprocessing. The package downloads these executables over unencrypted HTTP instead of secure HTTPS, allowing attackers positioned on the network to intercept the download and substitute malicious code. An attacker exploiting this could execute arbitrary code on systems running fis-sass-all, potentially compromising the entire build pipeline and deployed applications.
Technical details
The vulnerability is a cleartext protocol weakness (CWE-311, CWE-269) in which fis-sass-all fetches executable resources over HTTP rather than HTTPS. An attacker with network access—such as one on a compromised network, public Wi-Fi, or with ISP-level privileges—can perform a man-in-the-middle attack to intercept and replace the downloaded executable with a malicious binary. This results in arbitrary code execution in the context of the user running the package, with no authentication or user interaction required. The advisory states no patch is available; the vulnerability affects all versions up to and including 0.2.0, and the recommended mitigation is to avoid using the package or restrict its use to private networks only.
Affected products
- fis-dev fis-sass-all <=0.2.0
Timeline
- 2018-08-17: disclosed
- other: No patch available as of advisory date