
CVE-2018-8021 概念実証とエクスプロイト
IBM : Apache Superset は、pickle ライブラリの安全でない load メソッドを使用してデータをデシリアライズするため、リモートの攻撃者がシステム上で任意のコードを実行可能にする可能性があります。特別に細工されたリクエストを送信することで、攻撃者はこの脆弱性を悪用してシステム上で任意のコードを実行できます。
usage: exploit.py [-h] -t TCP -tp TPORT -i IP -p PORT -U USER -P PASSW
optional arguments:
-h, --help show this help message and exit
-t TCP, --tcp TCP tcp ip for shell
-tp TPORT, --tport TPORT
tcp port for shell
-i IP, --ip IP ip
-p PORT, --port PORT port
-U USER, --user USER User belong to Superset
-P PASSW, --passw PASSW
password of the user !
注意 : ユーザーとパスワードは、Superset でダッシュボードをインポートできるユーザーに属している必要があります!!!
元の PoC は David May 氏によって書かれました [[email protected]][https://github.com/DavidMay121]