Junglewise Threat Intelligence

CVE-2016-10691: windows-seleniumjar insecure HTTP executable download

CVE-2016-10691 · Severity: low · CVSS 3 · Published 2018-07-31

Vendors: npm.

Executive brief

windows-seleniumjar is a Node.js package that downloads Selenium WebDriver executables for Windows automation. The package downloads these executables over unencrypted HTTP, allowing attackers on the same network to intercept and replace the executable with malicious code, achieving arbitrary code execution on the host system.

Technical details

windows-seleniumjar suffers from missing encryption of sensitive data (CWE-311) when downloading executable resources. The package retrieves Selenium WebDriver binaries over unencrypted HTTP connections without integrity verification. An attacker with a privileged network position (man-in-the-middle) can intercept HTTP responses and substitute a malicious executable, which executes with the privileges of the user running the package. No patch is available; the advisory recommends avoiding this package entirely or limiting its use to trusted private networks where network-level compromise is less likely.

Affected products

  • npm windows-seleniumjar <= 2.48.2

Timeline

  • 2018-07-31: disclosed
  • 2018-07-31: advisory: GitHub Advisory Database published