Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThnZjQtcGNqNi01NHJw

Downloads Resources over HTTP in strider-sauce

Affected versions of strider-sauce insecurely download an executable over an unencrypted HTTP connection.

In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running strider-sauce.

Recommendation

While the package author has created a patch for this vulnerability, they have not yet published it to npm or bumped the version number.

In order to resolve the vulnerability, you will need to install the module manually from github:

npm install github:Strider-CD/strider-sauce#5ff6d65

As this vulnerability does not have a version bump included with the patch, it is possible that you have received a report for a vulnerable package, yet have installed the patched version and are no longer vulnerable. If that is the case, this advisory can be disregarded.

Permalink: https://github.com/advisories/GHSA-8gf4-pcj6-54rp
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThnZjQtcGNqNi01NHJw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 5 years ago
Updated: over 1 year ago


CVSS Score: 8.1
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-8gf4-pcj6-54rp, CVE-2016-10611
References: Blast Radius: 5.7

Affected Packages

npm:strider-sauce
Dependent packages: 2
Dependent repositories: 5
Downloads: 19 last month
Affected Version Ranges: <= 0.6.2
No known fixed version
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.3.1, 0.4.0, 0.4.1, 0.5.0, 0.5.1, 0.6.0, 0.6.1, 0.6.2