Skip to content

Downloads Resources over HTTP in iedriver

High severity GitHub Reviewed Published Feb 18, 2019 • Updated Jan 8, 2021

Package

npm iedriver (npm)

Affected versions

< 3.0.0

Patched versions

3.0.0

Description

Affected versions of iedriver insecurely download an executable over an unencrypted HTTP connection.

In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running iedriver.

Recommendation

Update to iedriver version 3.0.0 or greater.

References

Severity

High

Weaknesses

CVE ID

CVE-2016-10562

GHSA ID

GHSA-jfgq-g48x-jq83

Source code

No known source code
Checking history
See something to contribute? Suggest improvements for this vulnerability.