Vulnerabilities/

appium-chromedriver downloads Resources over HTTP

Severity:
High

Description

Affected versions of appium-chromedriver insecurely download resources over HTTP.

In scenarios where an attacker has a privileged network position, they can modify or read items send over HTTP at will. In this case, that includes the chromedriver binary, which may result in remote code execution if overwritten with a malicious binary.

Recommendation

Update the appium-chromedriver package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
appium-chromedriver
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing