Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2026-56139 — CVE-2026-56139(Apache Camel camel-undertow Rest DSL)のPoC再現コード:Rest DSLバインディングはmuteException=falseをハードコードしているため、設定されたmuteException=trueは無視され、捕捉されなかった例外の完全なスタックトレースがクライアントに返されます(CWE-209)。4.14.8/4.18.3/4.21.0で修正されました。 | Kitploit
ツール/GitHubGitHub/oscerd/cve-2026-56139
脆弱性分析エクスプロイト情報収集ウェブセキュリティペネトレーションテスト学習と教育
GitHuboscerd/cve-2026-56139

CVE-2026-56139

CVE-2026-56139(Apache Camel camel-undertow Rest DSL)のPoC再現コード:Rest DSLバインディングはmuteException=falseをハードコードしているため、設定されたmuteException=trueは無視され、捕捉されなかった例外の完全なスタックトレースがクライアントに返されます(CWE-209)。4.14.8/4.18.3/4.21.0で修正されました。

リポジトリを見る
102ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

camel-undertow Rest DSL muteException スタックトレース開示再現器 (CVE-2026-56139)

このプロジェクトは、Apache Camel の camel-undertow Rest DSL コンシューマにおける 情報漏洩 の問題を示しています。追跡番号は CVE-2026-56139 です。muteException オプションは、キャッチされなかった処理例外の詳細を HTTP クライアントに返すかどうかを制御します。プレーンな undertow エンドポイントではこのオプションは機能しますが、undertow Rest DSL は muteException が ハードコードで false に設定された応答バインディングを作成し、設定値をコピーしないため、REST モードでは muteException が静かに無視され、完全な Java スタックトレースが返されてしまいます。

// UndertowComponent (affected 4.18.2) — the Rest DSL binding is created without the endpoint's muteException
if (!map.containsKey("undertowHttpBinding")) {
    endpoint.setUndertowHttpBinding(new RestUndertowHttpBinding(endpoint.isUseStreaming()));  // muteException stays false
}

エンドポイントの undertowHttpBinding が非 null になったため、UndertowEndpoint.getUndertowHttpBinding() はその Rest バインディングをそのまま返し、エンドポイントの muteException をコピーするブランチを実行しません。そのため、明示的に muteException=true を設定したルートでも、Rest DSL 経由で提供されるとスタックトレースが漏洩し、内部のバックエンドホスト名、データベース URL、認証情報/ボルトのヒント、ライブラリバージョン、ソースの場所などが開示されます。

この PoC は、エラーメッセージによる情報漏洩 (CWE-209) としての影響を示しています。これは、CVE-2026-49365(プレーンな camel-netty-http および camel-undertow エンドポイントの muteException デフォルトを修正)の Rest DSL 固有の対応物です。両方は CAMEL-23651 の下で一緒に修正されました。

Advisory: https://camel.apache.org/security/CVE-2026-56139.html

脆弱性の概要

プロパティ値
コンポーネントcamel-undertow (Rest DSL コンシューマ)
影響を受けるクラスorg.apache.camel.component.undertow.UndertowComponent — muteException をコピーせずに RestUndertowHttpBinding を作成する(そのためデフォルトは false)
CWECWE-209 (機密情報を含むエラーメッセージの生成)
影響muteException=true が設定されていても、認証されていないクライアントに完全な Java スタックトレースが返される
前提条件undertow Rest DSL コンシューマであり、処理例外をトリガーする任意のリクエスト
影響を受けるバージョン4.0.0 から 4.14.8 未満、4.15.0 から 4.18.3 未満、4.19.0 から 4.21.0 未満
修正済みバージョン4.14.8, 4.18.3, 4.21.0
JIRACAMEL-23651 (PR apache/camel#23913)
報告者Yu Bao (PayPal)

修正により、Rest DSL パスが endpoint.getMuteException() を RestUndertowHttpBinding にコピーするようになり、Rest DSL が設定(および修正されたデフォルトの true)を尊重するようになります。

脆弱性のあるルート

// Both configured with muteException=true (camel.component.undertow.mute-exception=true):
restConfiguration().component("undertow").host("0.0.0.0").port(8888);
rest("/api").get("/orders").to("direct:boom");            // Rest DSL — IGNORES muteException, leaks
from("direct:boom").process(new FailingProcessor());

from("undertow:http://0.0.0.0:8889/plain/orders")         // plain endpoint — HONOURS muteException, empty body
    .process(new FailingProcessor());

リポジトリ構成

CVE-2026-56139/
├── pom.xml                 # camel-undertow 4.18.2
├── Dockerfile
├── docker-compose.yml      # single self-contained service
├── README.md
└── src/main/
    ├── java/com/example/
    │   ├── Application.java
    │   ├── FailingProcessor.java   # throws an exception carrying sensitive internal detail
    │   ├── RestRoutes.java         # undertow Rest DSL (:8888) + plain undertow endpoint (:8889)
    │   └── ExploitController.java  # attacker: GETs both, shows Rest DSL leaks while plain is muted
    └── resources/
        └── application.properties  # camel.component.undertow.mute-exception=true

前提条件

  • Docker と Docker Compose
  • Java 17+ と Maven 3.8+

再現手順

mvn clean package -DskipTests
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

期待される出力(要約)

1) undertow Rest DSL :8888  (muteException=true, but the Rest binding hard-codes false)
     HTTP 500
     response body (NNNN bytes) — LEAKS internal detail:
       | java.lang.IllegalStateException: Inventory lookup failed: cannot connect to
       |   jdbc:postgresql://prod-db.internal:5432/inventory (user=svc_inventory, ...)
       | 	at com.example.FailingProcessor.process(FailingProcessor.java:...)
       | 	...[truncated]

2) plain undertow endpoint :8889  (same muteException=true — honoured)
     HTTP 500
     response body: <empty>

>>> Information disclosure: true

推奨される修正

4.14.8 / 4.18.3 / 4.21.0 (CAMEL-23651) にアップグレードしてください。アップグレード後、undertow Rest DSL は muteException を尊重し(デフォルトは true)、スタックトレースは返されなくなります。

回避策

アップグレードするまでは、onException(...).handled(true)(またはグローバルエラーハンドラ)を追加して、スタックトレースの代わりに汎用メッセージを返すようにし、undertow Rest DSL コンシューマでは muteException だけに依存しないでください。

免責事項

この再現器は、セキュリティ研究および許可されたテストのみのために提供されており、公開され修正された脆弱性のためのものです。明示的な許可なくシステムに対して使用しないでください。

ツールをダウンロード