[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication RCE in Plastic SCM (Unity Version Control On-Prem) 11.0.16.10303 (Unity Technologies)



0day Rubbish Research Team is publicly disclosing a vulnerability in Plastic 
SCM (Unity Version Control On-Prem) 11.0.16.10303 (Unity Technologies). The 
research is published and a proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

Plastic SCM ships a self-developed binary version-control protocol on port 
8087, reachable by default on 0.0.0.0. Under the default NameWorkingMode, the 
server validates only that a client-declared username maps to a local OS 
account and never checks a password; LocalGroupSEIDProvider.CheckPassword is an 
empty no-op. Combined with a default EVERYBODY ACL that grants ALL_PERMISSIONS 
(including mktrigger) to any name-only-authenticated user, an unauthenticated 
attacker can declare an administrative username (leaked unauthenticated via 
GetRepositoryServerInfo), create a server-side trigger whose Path is fully 
attacker-controlled, and trigger it with a repository operation. 
TriggerProcess.ExecuteTrigger feeds the Path straight into Process.Start as the 
FileName with no sandbox, path allowlist, or signature check, yielding RCE as 
the plasticd service account (Linux: plasticscm uid=217; Windows: local 
Administrator). The only non-network prerequisite is one local OS username, 
which the pro
 tocol itself leaks.

Impact: Full compromise of the version-control server and all repositories, and 
arbitrary command execution as the plasticd service account; the attacker can 
read source code and repository metadata, create triggers, alter repositories, 
and persist access.

Advisory: https://0day-rubbish.com/blog/plastic-scm-unauth-8087-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/