QID 983413
QID 983413: Nodejs (npm) Security Update for operadriver (GHSA-2wrq-wmqf-8vcc)
operadriver is a Opera Driver for Selenium.
operadriver versions below 0.2.3 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
## Recommendation
Update to version 0.2.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2wrq-wmqf-8vcc for updates pertaining to this vulnerability.
Vendor References
- GHSA-2wrq-wmqf-8vcc -
github.com/advisories/GHSA-2wrq-wmqf-8vcc
CVEs related to QID 983413
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2wrq-wmqf-8vcc | operadriver |
|