PT-2018-4789 · Strider Cd · Strider-Sauce

Published

2018-05-29

·

Updated

2019-10-09

·

CVE-2016-10611

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions strider-sauce versions prior to the patched version
Description The issue allows for a man-in-the-middle (MITM) attack due to the insecure download of zipped resources over HTTP. This could potentially lead to remote code execution (RCE) if an attacker swaps the requested zip file with a malicious one, particularly if the attacker is on the network or positioned between the user and the remote server. In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running strider-sauce.
Recommendations To resolve the vulnerability, install the module manually from github using the command: npm install github:Strider-CD/strider-sauce#5ff6d65 Note that due to the lack of a version bump with the patch, you may have already installed the patched version and can disregard this advisory if that is the case.

Fix

Missing Encryption of Sensitive Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10611
GHSA-8GF4-PCJ6-54RP

Affected Products

Strider-Sauce