T08 · Insecure Dependencies
- Location
references/setup.md:16- Finding
Aliyun CLI Binary Installed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
references/setup.md:16-23
Vulnerability Type: Unverified third-party binary installation
Risk Level: MediumVulnerable Code
bash # Option 2: manual binary install (amd64) curl -Lo aliyun-cli.tgz https://github.com/aliyun/aliyun-cli/releases/latest/download/aliyun-cli-linux-latest-amd64.tgz tar xzf aliyun-cli.tgz sudo mv aliyun /usr/local/bin/ # For arm64 curl -Lo aliyun-cli.tgz https://github.com/aliyun/aliyun-cli/releases/latest/download/aliyun-cli-linux-latest-arm64.tgz tar xzf aliyun-cli.tgz sudo mv aliyun /usr/local/bin/Technical Analysis
The installation instructions retrieve a binary archive from a mutable
latestrelease URL, extract it, and move the resulting executable into the privileged/usr/local/bindirectory. No cryptographic checksum, digital signature, pinned version, or archive-content validation is performed.Although the URL points to the official Aliyun CLI GitHub repository, the process does not independently verify artifact integrity. Compromise of the upstream release account, release pipeline, hosted artifact, or another trusted delivery component could therefore result in an altered executable being installed.
Moving the unchecked executable into
/usr/local/binalso gives it a trusted position in the system command search path. When subsequently invoked, the binary may have access to Alibaba Cloud credentials, profiles, environment variables, and all cloud privileges assigned to the current identity.Attack Path
- An attacker compromises or replaces an artifact available through the mutable release URL or another trusted supply-chain component.
- A user follows the documented installation procedure.
- The modified archive is downloaded without checksum or signature validation.
- The attacker-controlled executable is installed as
/usr/local/bin/aliyun. - The user invokes
aliyunwhile authenticate ...[truncated 938 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the download to an explicit, reviewed Aliyun CLI version instead of using a mutable
latestURL. - Obtain the expected SHA-256 digest from an authenticated, publisher-controlled source.
- Verify the digest before extraction and terminate installation on mismatch.
- Verify a publisher-provided digital signature when available.
- Extract into a newly created restricted temporary directory and validate the archive contents before installation.
- Ensure that the archive cannot overwrite paths outside the intended extraction directory.
- Prefer a trusted package manager that validates signed repository metadata and package integrity.
- Document the expected version after installation and confirm it with
aliyun version.
- Pin the download to an explicit, reviewed Aliyun CLI version instead of using a mutable
