[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation)



0day Rubbish Research Team is publicly disclosing a vulnerability in Apache 
Struts 2 2.6.11.0 (Apache Software Foundation). The research is published and a 
proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

Apache Struts 2.6.11.0 is vulnerable to unauthenticated remote code execution 
under a documented REST mapper configuration combined with wildcard dynamic 
dispatch. RestfulActionMapper.getMapping() extracts the action name from the 
request URI without calling cleanupActionName, the character-set gate that 
DefaultActionMapper adopted after S2-057; that fix was never synchronized to 
the REST mapper. When an application uses struts.mapper.class=restful with a 
wildcard action and a result containing {1} substitution, attacker-controlled 
OGNL metacharacters flow through the wildcard capture into 
TextParseUtil.translateVariables, bypassing AcceptedPatternsChecker. A novel 
java.beans.Expression/Statement reflection primitive then defeats the 
SecurityMemberAccess sandbox and reaches Runtime.exec. The chain was verified 
with uid=0(root) on a Tomcat 9 / OGNL 3.3.5 deployment. The only precondition 
is an opt-in but documented configuration subset (REST mapper plus wildcard 
dynamic dispatch).

Impact: Arbitrary operating system command execution as the JVM process user; 
on a root-run deployment, full host compromise. No credentials are required.

Advisory: https://0day-rubbish.com/blog/apache-struts2-restful-mapper-ognl-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/