T08 · Insecure Dependencies
- Location
references/cli-installation-guide.md:38- Finding
Mutable Aliyun CLI Binary Is Installed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
references/cli-installation-guide.md:21-30, 38-45, 51-58, 64-71
Vulnerability Type: Unverified third-party binary installation
Risk Level: HighVulnerable Code
bash # Download wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz # Extract and install tar -xzf aliyun-cli-linux-latest-amd64.tgz sudo mv aliyun /usr/local/bin/ # Verify aliyun versionEquivalent unverified installation procedures are also provided for macOS, CentOS/RHEL, ARM64 Linux, and Windows.
Technical Analysis
The guide downloads a mutable archive identified as
latest, extracts it, and places the resulting executable in the privileged/usr/local/bindirectory. It does not pin a specific release, validate a publisher-provided checksum, or verify a cryptographic signature.HTTPS authenticates the transport endpoint but does not make the artifact reproducible or protect users if the CDN, release pipeline, origin server, or associated credentials are compromised. Running
aliyun versionafter installation confirms only that the binary executes; it does not establish authenticity.The installed CLI subsequently receives Alibaba Cloud credentials and invokes APIs capable of creating and deleting VPN gateways, customer gateways, VPN connections, and routes.
Attack Path
- An attacker compromises the binary distribution origin, CDN, DNS path, TLS termination point, or release process.
- The attacker replaces the mutable
latestarchive with one containing a modifiedaliyunexecutable. - A user follows the guide and downloads the archive without validating its digest or signature.
- The executable is moved into
/usr/local/bin, making it available system-wide. - The user or Agent executes the substituted binary during version checks and later cloud operations.
- The malicious binary captures cloud credentials, changes requested API operations, ...[truncated 666 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin an exact Aliyun CLI release rather than downloading a mutable
latestarchive. - Publish the expected SHA-256 or stronger digest in the guide and verify it before extraction.
- Prefer publisher-signed packages or releases and verify the signature against a separately obtained, trusted signing key.
- Use an operating-system package manager or other authenticated package repository where available.
- Download into a dedicated temporary directory with restrictive permissions.
- Inspect the archive contents before extraction and reject unexpected paths or files.
- Install only after verification succeeds, and fail closed if no trusted checksum or signature is available.
- Document a secure upgrade process that applies the same pinning and verification controls.
- Pin an exact Aliyun CLI release rather than downloading a mutable
