Junglewise Threat Intelligence

CVE-2017-16040: gfe-sass insecure HTTP resource download

CVE-2017-16040 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

gfe-sass is a Node.js library for SASS processing. The package insecurely downloads executable files over unencrypted HTTP, allowing attackers with network access to intercept and replace downloads with malicious code, leading to arbitrary code execution on systems where the library is installed.

Technical details

This vulnerability is classified as CWE-311 (Missing Encryption of Sensitive Data). The root cause is that gfe-sass downloads an executable resource over an unencrypted HTTP connection rather than HTTPS. An attacker positioned on the network path (man-in-the-middle) can intercept the HTTP response and inject a malicious executable, which is then executed during package installation or runtime. The attack requires network-level access or a compromised network link. No patch is available for this vulnerability, and the maintainers recommend avoiding the package entirely or restricting its use to private networks only.

Affected products

  • npm gfe-sass all versions (0.0.0 and later)

Timeline

  • 2020-09-01: disclosed

References