GHSA-7p6h-3fmw-539q
Dashboard / Vulnerabilities / GHSA-7p6h-3fmw-539q
Summary: selenium-chromedriver Downloads Resources over HTTP
Details: Affected versions of `selenium-chromedriver` insecurely download an executable over an unencrypted HTTP connection. In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `selenium-chromedriver`. ## Recommendation No patch is currently available for this vulnerability, and the author has marked the package as deprecated. The best mitigation is currently to avoid using this package, using a different package if available. Alternatively, the risk of exploitation can be reduced by ensuring that this package is not installed while connected to a public network. If the package is installed on a private network, the only people who can exploit this vulnerability are those who have compromised yo
References: https://nvd.nist.gov/vuln/detail/CVE-2016-10624, https://github.com/advisories/GHSA-7p6h-3fmw-539q, https://www.npmjs.com/advisories/222
Affected packages
Package
Name: selenium-chromedriver
Purl: pkg:npm/selenium-chromedriver
Affected ranges
Type: SEMVER
Events:
