From fe2a9c086712702bc11619a73fe31e063175964d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 3 Oct 2024 22:22:53 +0000 Subject: [PATCH] Publish GHSA-fm76-w8jw-xf8m --- .../GHSA-fm76-w8jw-xf8m.json | 88 +++++++++++++++++++ 1 file changed, 88 insertions(+) create mode 100644 advisories/github-reviewed/2024/10/GHSA-fm76-w8jw-xf8m/GHSA-fm76-w8jw-xf8m.json diff --git a/advisories/github-reviewed/2024/10/GHSA-fm76-w8jw-xf8m/GHSA-fm76-w8jw-xf8m.json b/advisories/github-reviewed/2024/10/GHSA-fm76-w8jw-xf8m/GHSA-fm76-w8jw-xf8m.json new file mode 100644 index 00000000000..8fcdcd16868 --- /dev/null +++ b/advisories/github-reviewed/2024/10/GHSA-fm76-w8jw-xf8m/GHSA-fm76-w8jw-xf8m.json @@ -0,0 +1,88 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm76-w8jw-xf8m", + "modified": "2024-10-03T22:21:24Z", + "published": "2024-10-03T22:21:24Z", + "aliases": [ + + ], + "summary": "@saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plugins using git source", + "details": "### Summary\n\nWhen creating a new plugin using the `git` source, the user-controlled value `req.body.name` is used to build the plugin directory where the location will be cloned. The API used to execute the `git clone` command with the user-controlled data is `child_process.execSync`. Since the user-controlled data is not validated, a user with admin permission can add escaping characters and execute arbitrary commands, leading to a command injection vulnerability.\n\n### Details\n\nRelevant code from source (`req.body`) to sink (`child_process.execSync`).\n\n- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/server/routes/plugins.js#L1400\n\n```js\nrouter.post(\n \"/\",\n isAdmin,\n error_catcher(async (req, res) => {\n const plugin = new Plugin(req.body); // [1] \n [...]\n try {\n await load_plugins.loadAndSaveNewPlugin( // [3] \n plugin,\n schema === db.connectObj.default_schema || plugin.source === \"github\"\n );\n [...]\n }\n })\n);\n```\n\n- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/saltcorn-data/models/plugin.ts#L44\n```js\nclass Plugin {\n [...]\n constructor(o: PluginCfg | PluginPack | Plugin) {\n [...]\n this.name = o.name; // [2] \n [...]\n}\n```\n\n- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/server/load_plugins.js#L64-L65\n```js\nconst loadAndSaveNewPlugin = async (plugin, force, noSignalOrDB) => {\n [...]\n const loader = new PluginInstaller(plugin); // [4] \n const res = await loader.install(force); // [7] \n [...]\n};\n```\n\n- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/plugins-loader/plugin_installer.js#L41-L61\n```js\nclass PluginInstaller {\n constructor(plugin, opts = {}) {\n [...]\n const tokens =\n plugin.source === \"npm\"\n ? plugin.location.split(\"/\")\n : plugin.name.split(\"/\"); // [5] \n [...]\n this.tempDir = join(this.tempRootFolder, \"temp_install\", ...tokens); // [6] \n [...]\n }\n\n \n async install(force) {\n [...]\n if (await this.prepPluginsFolder(force, pckJSON)) { // [8] \n [...]\n }\n\n async prepPluginsFolder(force, pckJSON) {\n [...]\n switch (this.plugin.source) {\n [...]\n case \"git\":\n if (force || !(await pathExists(this.pluginDir))) { \n await gitPullOrClone(this.plugin, this.tempDir); // [9] \n\t [...]\n }\n```\n\n- file: https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/plugins-loader/download_utils.js#L112\n```js\nconst gitPullOrClone = async (plugin, pluginDir) => {\n [...]\n if (fs.existsSync(pluginDir)) {\n execSync(`git ${setKey} -C ${pluginDir} pull`);\n } else {\n execSync(`git ${setKey} clone ${plugin.location} ${pluginDir}`); // [10] \n }\n [...]\n};\n```\n\n### PoC\n\n- check that the file will be created by the command `echo \"hello\">/tmp/HACKED` does not exists:\n```\ncat /tmp/HACKED\ncat: /tmp/HACKED: No such file or directory\n```\n- login with an admin account\n- visit `http://localhost:3000/plugins/new`\n- enter the following fields:\n\t- Name: `;echo \"hello\">/tmp/HACKED`\n\t- Source: `git`\n\t- other fields blank\n- click `Create`\n- you will get an error saying `ENOENT: no such file or directory, ....` but the command `touch /tmp/HACKED` will be executed\n- to verify:\n```\ncat /tmp/HACKED\nhello\n```\n\n### Impact\n\nRemote code execution\n\n### Recommended Mitigation\n\nSanitize the `pluginDir` value before passing to `execSync`. Alternatively, use `child_process. execFileSync` API (docs: https://nodejs.org/api/child_process.html#child_processexecfilesyncfile-args-options)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@saltcorn/plugins-loader" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.0-beta.14" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.0.0-beta.13" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/security/advisories/GHSA-fm76-w8jw-xf8m" + }, + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/commit/024f19a7e079913f62f4a2335ab04116ddb68192" + }, + { + "type": "PACKAGE", + "url": "https://github.com/saltcorn/saltcorn" + }, + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/plugins-loader/download_utils.js#L112" + }, + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/plugins-loader/plugin_installer.js#L41-L61" + }, + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/saltcorn-data/models/plugin.ts#L44" + }, + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/server/load_plugins.js#L64-L65" + }, + { + "type": "WEB", + "url": "https://github.com/saltcorn/saltcorn/blob/v1.0.0-beta.13/packages/server/routes/plugins.js#L1400" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-10-03T22:21:24Z", + "nvd_published_at": null + } +} \ No newline at end of file