QID 983456
QID 983456: Nodejs (npm) Security Update for chromedriver (GHSA-jh5w-6964-x5cf)
Affected versions of `chromedriver` insecurely download resources over HTTP.
In scenarios where an attacker has a privileged network position, they can modify or read such resources at will. This may result in arbitrary code execution if an attacker intercepts and modifies the downloaded binary file, replacing it with a malicious one.
## Recommendation
Update to version 2.26.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jh5w-6964-x5cf for updates pertaining to this vulnerability.
Vendor References
- GHSA-jh5w-6964-x5cf -
github.com/advisories/GHSA-jh5w-6964-x5cf
CVEs related to QID 983456
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jh5w-6964-x5cf | chromedriver |
|