PT-2018-4758 · Node Webkit · Nodewebkit

Publicado

2018-06-01

·

Atualizado

2019-10-09

·

CVE-2016-10580

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nodewebkit versions (affected versions not specified)
Description The issue allows for potential remote code execution (RCE) due to the insecure download of zipped resources over HTTP, making it susceptible to man-in-the-middle (MITM) attacks. If an attacker is positioned between the user and the remote server or is on the same network, they can potentially swap the requested zip file with an attacker-controlled zip file. This vulnerability can be exploited when an attacker has a privileged network position, allowing them to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running nodewebkit.
Recommendations As a temporary workaround, consider using the official installer instead of the nodewebkit package, as per the package author's instructions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10580
GHSA-GC6C-5V9W-XMHW

Produtos afetados

Nodewebkit