Junglewise Threat Intelligence

CVE-2023-45311: fsevents code injection via compromised binaries URL

CVE-2023-45311 · Severity: low · CVSS 3.1 · Published 2023-10-06

Vendors: npm.

Executive brief

fsevents is a Node.js library used by JavaScript projects to monitor file system changes. Versions before 1.2.11 rely on binaries hosted on an AWS S3 bucket that was not properly secured; if an attacker gained control of that URL, they could inject malicious code into projects that downloaded and distributed those binaries, leading to arbitrary code execution in any system using the affected package.

Technical details

The vulnerability is a code injection (CWE-94) stemming from insecure dependency resolution. fsevents before version 1.2.11 retrieves binary artifacts from an AWS S3 URL (https://fsevents-binaries.s3-us-west-2.amazonaws.com) without integrity verification or secure ownership controls. An adversary who could compromise or claim that URL could serve malicious binaries. Projects that depend on fsevents and lock those poisoned binaries in their package-lock.json files would distribute the malicious code to end users. The attack requires no user interaction or authentication—affected is any JavaScript project (and downstream consumers) that installed vulnerable fsevents versions. The fix, released in version 1.2.11, removes or secures the external binary dependency.

Affected products

  • fsevents fsevents before 1.2.11

Timeline

  • 2023-10-06: disclosed
  • 2023-10-06: patched

References