QID 983970
QID 983970: Nodejs (npm) Security Update for selenium-binaries (GHSA-h4mc-r4f4-hcf4)
Affected versions of `selenium-binaries` insecurely download an executable over an unencrypted HTTP connection. In scenarios where an attacker has a privileged network position, it is possible to intercept the response and replace the executable with a malicious one, resulting in code execution on the system running `selenium-binaries`. ## Recommendation No fix is currently available for this vulnerability. The best mitigation currently available is to use an alternate package, such as [selenium-webdriver](https://www.npmjs.com/package/selenium-webdriver), the official selenium bindings for node.js.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h4mc-r4f4-hcf4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h4mc-r4f4-hcf4 -
github.com/advisories/GHSA-h4mc-r4f4-hcf4
CVEs related to QID 983970
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h4mc-r4f4-hcf4 | selenium-binaries |
|