XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
BID:32101
Info
XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
| Bugtraq ID: | 32101 |
| Class: | Design Error |
| CVE: |
CVE-2008-6504 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2008 12:00AM |
| Updated: | Mar 14 2011 07:47PM |
| Credit: | Meder Kydyraliev, Google Security Team |
| Vulnerable: |
VMWare vCenter Orchestrator 4.1 VMWare vCenter Orchestrator 4.0 OpenSymphony XWork 2.0.5 OpenSymphony XWork 2.0.4 OpenSymphony XWork 2.0.3 OpenSymphony XWork 2.0.2 OpenSymphony XWork 2.0.1 Apache Software Foundation Struts 2.0.11 .2 Apache Software Foundation Struts 2.0.9 Apache Software Foundation Struts 2.0.8 Apache Software Foundation Struts 2.0.7 Apache Software Foundation Struts 2.0.6 Apache Software Foundation Struts 2.0.5 Apache Software Foundation Struts 2.0.4 Apache Software Foundation Struts 2.0.3 Apache Software Foundation Struts 2.0.2 Apache Software Foundation Struts 2.0.1 Apache Software Foundation Struts 2.0 |
| Not Vulnerable: |
OpenSymphony XWork 2.0.6 Apache Software Foundation Struts 2.0.12 |
Discussion
XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
XWork is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
Attackers can exploit this issue to manipulate server-side context objects with the privileges of the user running the application. Successful exploits can compromise the application and possibly the underlying computer.
Versions prior to XWork 2.0.6 are vulnerable. Struts 2.0.0 through 2.0.11.2 contain vulnerable versions of XWorks and are therefore also affected.
XWork is prone to a security-bypass vulnerability because it fails to adequately handle user-supplied input.
Attackers can exploit this issue to manipulate server-side context objects with the privileges of the user running the application. Successful exploits can compromise the application and possibly the underlying computer.
Versions prior to XWork 2.0.6 are vulnerable. Struts 2.0.0 through 2.0.11.2 contain vulnerable versions of XWorks and are therefore also affected.
Exploit / POC
XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
To exploit this issue, attackers can use readily available tools.
The following example statement is available:
To set #session.user to '0wn3d':
('\u0023' + 'session[\'user\']')(unused)=0wn3d
To exploit this issue, attackers can use readily available tools.
The following example statement is available:
To set #session.user to '0wn3d':
('\u0023' + 'session[\'user\']')(unused)=0wn3d
Solution / Fix
XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
Solution:
The vendor released XWork 2.0.6 to address this issue. Please see the references for more information.
Apache Software Foundation Struts 2.0
Apache Software Foundation Struts 2.0.1
Apache Software Foundation Struts 2.0.11 .2
Apache Software Foundation Struts 2.0.2
Apache Software Foundation Struts 2.0.3
Apache Software Foundation Struts 2.0.4
Apache Software Foundation Struts 2.0.5
Apache Software Foundation Struts 2.0.6
Apache Software Foundation Struts 2.0.7
Apache Software Foundation Struts 2.0.8
Apache Software Foundation Struts 2.0.9
Solution:
The vendor released XWork 2.0.6 to address this issue. Please see the references for more information.
Apache Software Foundation Struts 2.0
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.1
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.11 .2
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.2
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.3
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.4
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.5
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.6
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.7
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.8
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
Apache Software Foundation Struts 2.0.9
-
Apache Software Foundation struts-2.0.12-all.zip
http://people.apache.org/builds/struts/2.0.12/struts-2.0.12-all.zip
References
XWork 'ParameterInterceptor' Class OGNL Security Bypass Vulnerability
References:
References:
- XWork Homepage (OpenSymphony)
- XWork ParameterInterceptors bypass (OGNL statement execution) (Meder Kydyraliev, Google Security Team)
- S2-003 XWork ParameterInterceptors bypass allows OGNL statement execution (Apache Software Foundation)