èå¼±æ§ãå ±åãã¦åãã¦æ¡çªãããCVEã®è§£èª¬ã¨æ³¨æåèµ·
ãã®ããã°ã§ã¯ãä¹ ãã¶ãã§ããazaraã§ãã
è¿æ³ã®å ±åãªã©ã¯å¥ã®è¨äºã§æ¸ãã¨ãã¦ãæ¬è¨äºã¯IPFactory Advent Calendar 2020ã®17æ¥ç®ã®è¨äºã§ããIPFactoryã«é¢ãã¦ã¯ãã¡ããã覧ãã ããã
注æåèµ·
æ¬ããã°ã®å 容ã¯ã»ãã¥ãªãã£ã«é¢ããç¥è¦ãåºãå ±æããç®çã§å·çããã¦ãããèå¼±æ§ã®æªç¨ãªã©ã®æ»æè¡çºãæ¨å¥¨ãããã®ã§ã¯ããã¾ããã許å¯ãªããããã¯ãã«æ»æãå ããã¨ç¯ç½ªã«ãªãå¯è½æ§ãããã¾ããçè ãè¨è¼ããæ å ±ãåç §ã»æ¨¡å£ãã¦è¡ãããè¡çºã«é¢ãã¦çè ã¯ä¸å責任ãè² ãã¾ããã
ã¾ãã該å½è£½åã¯å¸¸ã«ä»åããèå¼±æ§ã¸ã®ä¿®æ£ãè¡ã£ã¦ãããããå½±é¿ã確ãããªããã¢ãããã¼ããè¡ããã¨ãå¼·ããå§ããã¾ãã
JVN#56450373 GROWI ã«ãããè¤æ°ã®èå¼±æ§ / JVN#94169589 GROWI ã«ãããè¤æ°ã®èå¼±æ§
ä»åæ¡çªãããCVE
- CVE-2020-5676
- CVE-2020-5677
- CVE-2020-5678
- CVE-2020-5682
èå¼±æ§è§£èª¬
ä»åå ±åããèå¼±æ§ã«ããã¦ãRCEãNoSQLiãªã©ã®èå¼±æ§ã¯å ±åãã¦ããªããããç·æ¥åº¦ã®é«ããã®ã§ã¯ããã¾ããããã ããæ»æææ³ã«é¢ãã¦ã¯ç°¡åãªãã®ãå¤ãã£ãããå ã®æ³¨æåèµ·ã§ãè¿°ã¹ãéããå½±é¿ã確ãããªããã¢ãããã¼ããè¡ããã¨ãå¼·ããå§ããã¾ãã
CVE-2020-5676
ã¦ã¼ã¶ã¼ãè¨å®ããéå ¬éç¶æ ã®emailãHTML常ã«è¡¨ç¤ºããã¦ããã¨ãããã®ã§ãã
åç¾æé
- ã¡ã¼ã«ã¢ãã¬ã¹ã®å ¬éãéå ¬éã«è¨å®
- å¥ã¢ã«ã¦ã³ãã§ãã°ã¤ã³ããå ç¨è¨å®ããã¦ã¼ã¶ã¼ã®ãã¼ã¸ãé²è¦§ãã
Devãã¼ã«ãªã©ã§HTMLã確èªããã¨ã¦ã¼ã¶ã¼æ å ±ãJSONå½¢å¼ã§è¡¨ç¤ºããã¦ããããã®ä¸ã«å ç¨è¨å®ããã¡ã¼ã«ã表示ããã¦ããã
ãªã¹ã¯
é éã®ç¬¬ä¸è ã«ãã£ã¦ãã¦ã¼ã¶ãéå ¬éã«ãã¦ããæ å ±ãçªåããã
ä¿®æ£ç¶æ³
emailã表示ããã¦ããid=content-main
ã確èªããã¨ãemailã表示ããã¦ããªããã¨ã確èªã§ãã¾ãã
CVE-2020-5677
Header ã¿ã°å ã«Pathãåºåãããéã®XSSãã£ã«ã¿ã¼ã®å¦çãä¸å®å ¨ãªç¶æ ã ã£ãããHTMLã¿ã°ãåºåããã¦ãã¾ããXSSãå®è¡ã§ãã¦ãã¾ãèå¼±æ§ã§ããã
Pathãtitleã«è¡¨ç¤ºãããã¼ã¸å ¨è¬ã§çºçããæ»æã®ææ³ã¨ãã¦ã¯ç°¡åã«å®è¡ã§ãã¦ãã¾ãã¾ãã
Plane : http://localhost:3000/Sandbox</title</s>><script<s>>alert(1);</script</s>>
URL encode: http://localhost:3000/Sandbox%3C/title%3C/s%3E%3E%3Cscript%3Cs%3E%3Ealert(1);%3C/script%3C/s%3E%3E
åç¾æé
å ±åå½æã®Growiã§ã¯XSS対çã®ããã«ã¿ã°æå(ä¾: <s>
ã®ããã«å®å
¨ã«éãããããã®)ãåé¤ããã¨ããæ©æ§ãããã¾ããã
å®éã«ãªã¯ã¨ã¹ããæããã¨æ¬¡ã®ããã«è¡¨ç¤ºããã¾ãã
URL: http://localhost:3000/Sandbox%3Cs%3Ehoge%3C/s%3E
CTFã®åé¡ã§ã¿ããã¨ã®ããæåã ã£ãã®ã§è©¦ãã«<s<s>>hoge</s<s>>
ã®ãããªå½¢å¼ã§å
¥åããã¦ã¿ã¾ããã
URL: http://localhost:3000/Sandbox%3Cs%3Cs%3E%3Ehoge%3C/s%3Cs%3E%3E
ããã¨ç´ ç´ã«ã¿ã°ã表示ãããããã«ãªãã¾ããããã¨ã¯</title>
ã§ã¿ã°ãéãããã<script></script>
ãæ¿å
¥ã§ããã°XSSãã§ãã¾ãã
ããã§ãã®æ©æ§ãåé¿ããããã«</title<s>><script<s>>alert(1)</script<s>>
ã®ãããªå
¥åãURLã«è¡ãã¾ããã
URL: http://localhost:3000/Sandbox%3C/title%3Cs%3E%3E%3Cscript%3Cs%3E%3Ealert(1)%3C/script%3Cs%3E%3E
ããã¨alert(1)
ã®è¡¨ç¤ºããããã¢ãããã¾ãã
HTMLã®è¡¨ç¤ºã確èªããã¨ãHTMLã¿ã°ã表示ããã¦ããXSSãä½åãã¦ãããã¨ã確èªã§ãã¾ãã
ãªã¹ã¯
å½è©²è£½åã使ç¨ãã¦ãããµã¤ãã«ã¢ã¯ã»ã¹ããã¦ã¼ã¶ã®ã¦ã§ããã©ã¦ã¶ä¸ã§ãä»»æã®ã¹ã¯ãªãããå®è¡ããã ã
ä¿®æ£ç¶æ³
/
ããå³ã«ä½ç½®ããæååã®ã¿<title>
å
ã«è¡¨ç¤ºãããã¨ã§ä¿®æ£ããã¦ãã¾ããã
CVE-2020-5678
ãã¼ã¸ã®é
ä¸ã«ãããã¼ã¸ããªã¹ãã§è¡¨ç¤ºããç®æã§çºçããXSSã§ãå
ã®CVE-2020-5677
ã®çºå±ã§çºè¦ãããã®ã§ãã
åç¾æé
XSSãã£ã«ã¿ã¼èªä½ããã¼ã¯ãã¦ã³ã«ã¯æå¹ã§ããããã以å¤ã®é¨åã§ã¯CVE-2020-5677
åæ§ã®XSSã¸ã®å¯¾çæ©æ§ãå©ç¨ãã¦ãã¾ããã
æ¤è¨¼ã®ãããã¾ãåãã«<s>test1</s>
ã®ãããªã¿ã¤ãã«ã¦æ°è¦ãã¼ã¸ãä½ã£ã¦ã¿ã¾ãããã
ããã¨Pathã§ã¯<s>test1</s>
ã®URLã¨ã³ã³ã¼ããããæååãè¦ãã¾ãã
ããããHTMLã®è¡¨ç¤ºä¸ã¯åæ ããã¦ããªãããã§ãã
ãã®ãã¨æ°è¦ä½æãããéã®ãªã¯ã¨ã¹ããè¦ã¦ãã<s>
ã¿ã°ã¯åé¤ããã¦éä¿¡ããã¦ãã¾ãã
ãªã¹ãã®è¡¨ç¤ºä¸ãå½ç¶ãæã¡æ¶ããã¦ãã¾ããã
次ã«å
ç¨ã®CVE-2020-5677
åæ§ã«<s<s>>test2</s<s>>
ã®ãããªå½¢å¼ã§ãã¼ã¸ãä½æãã¾ãããã
æå符å·åã¯ãã¦ããã§ãã表示ããã¦ããã®ããããã¾ãã
ä¸é¨ã§ã¯ããã¾ããHTMLä¸ã«è¡¨ç¤ºããã¦ããPathãè¦ã¦ãæå符å·ã«ãªã£ã¦ãã¾ãã
ãªã¯ã¨ã¹ããã¿ãã¨<s>test2</s>
ã¨ãªã£ã¦ããã®ã§ããããããã¨æããªã¹ããè¦ã«è¡ãã¾ãã
確èªãããã¨ã<s>
ã¿ã°ã¯ãã£ããã¨åé¤ããã¦ãã¾ãã
æå¾ã®ç¢ºèªã¨ãã¦ãCVE-2020-5677
ããããä¸ã¤<s>
ã¿ã°ãå¢ãããã¼ã¸ãä½æãã¾ãã
å®éã«æ°è¦ä½æããã¦ã¿ãã¨<s>
ã¿ã°ãæã¡æ¶ãç·ãå¼ãã¦ããã®ããããã¾ãã
æå¾ã«<script<s<s>>>alert(1)</script<s<s>>>
ã§ãã¼ã¸ãä½ã£ã¦ã¿ã¾ãããã
ã§ã¾ããã
ä¿®æ£ç¶æ³
ãã¼ã¸åã«å«ã¾ããã¿ã°æåããªã¹ãã«è¡¨ç¤ºãããå ´åã¯åé¤ãããç¶æ ã§è¡¨ç¤ºãããããã«ãªã£ã¦ããã
CVE-2020-5682
Growiã§ã¯è¨äºã«å¯¾ãã¦ã¿ã°ãä»ä¸ãããã¨ãã§ãã¾ãããã®ã¿ã°ãæ¤ç´¢ããAPIã§ã¯ãmongodbã®æ£è¦è¡¨ç¾æ¤ç´¢ãå©ç¨ãã¦ããããã®æ¤ç´¢ã®éã«APIã®æ£è¦è¡¨ç¾ãç´æ¥å©ç¨ãã¦ããããDoSãå¼ãèµ·ãããã¨ãã§ãã¾ããã
è¬è¾
èå¼±æ§ã®ä¿®æ£ãè¡ã£ã¦ãã ãã£ãéçºè ã®çæ§ãããã¦é¢é£ããæ¥åããµãã¼ãããã¦ãã ãã£ãJPCERT/CC,IPAã®çæ§ã«å¿ããæè¬ç³ãä¸ãã¾ãã
ãããã¨ããããã¾ãã
ã¾ãã注æåèµ·ã®ãã詳細ã®é示ã許ãã¦ããã ããGrowiã®éçºé£ã«ã¯æ¹ãã¦æè¬ç³ãä¸ãã¾ãã