Malicious Node.js Module Exploits Environment Variables in OpenSSL by Node.js
CVE-2017-16064

7.5HIGH

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
7 June 2018

What is CVE-2017-16064?

The vulnerability involves a malicious module within the Node.js ecosystem, specifically node-openssl, designed to compromise the security of environment variables. This module had the potential to be exploited for malicious purposes, such as injecting unauthorized commands or accessing sensitive data. It was subsequently removed from the npm repository upon discovery, but it served as a critical reminder of the importance of vetting third-party modules in the Node.js environment.

Affected Version(s)

node-openssl node module All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.