Junglewise Threat Intelligence

CVE-2016-10693: pm2-kafka insecure HTTP resource download

CVE-2016-10693 · Severity: info · CVSS 7.4 · Published 2020-09-01

Vendors: npm.

Executive brief

pm2-kafka is a Node.js library for Apache Kafka integration. The library downloads executable resources over unencrypted HTTP, allowing attackers on privileged network positions to intercept and replace the executable with malicious code, leading to complete system compromise.

Technical details

pm2-kafka insecurely downloads an executable over an unencrypted HTTP connection (CWE-311: Missing Encryption of Sensitive Data). An attacker with a privileged network position (man-in-the-middle) can intercept the HTTP response and replace the executable with a malicious one, achieving arbitrary code execution on the host running pm2-kafka. This requires network-level access during package installation but no authentication. No patch is currently available; the advisory recommends avoiding the package or restricting its use to private networks.

Affected products

  • npm pm2-kafka all versions

Timeline

  • 2020-09-01: disclosed
  • other: CVE-2016-10693 assigned earlier, published via GHSA in 2020

References