Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: Request GoAnywhere MFT RCE (CVE-2023-0669) #540

Open
SuperX-SIR opened this issue Sep 20, 2024 · 5 comments · May be fixed by #541
Open

PRP: Request GoAnywhere MFT RCE (CVE-2023-0669) #540

SuperX-SIR opened this issue Sep 20, 2024 · 5 comments · May be fixed by #541
Assignees
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue).

Comments

@SuperX-SIR
Copy link
Contributor

Hello.
I want to contribute to the tsunami scanner with a detector plugin to detect CVE-2023-0669 vulnerability

Reference

https://nvd.nist.gov/vuln/detail/CVE-2023-0669
https://www.vicarius.io/vsociety/posts/unauthenticated-rce-in-goanywhere
https://www.cve.org/CVERecord?id=CVE-2023-0669

Description

The vulnerability has been assigned a CVE ID CCVE-2023-0669 , the severity level of the vulnerability is 7.2 HIGH : CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

This is pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object

versions

version 7.1.1 and its earlier versions

@tooryx
Copy link
Member

tooryx commented Sep 25, 2024

Hi @SuperX-SIR,

Would you be willing to first contribute to fingerprints for the software?

Thanks
~tooryx

@SuperX-SIR
Copy link
Contributor Author

SuperX-SIR commented Sep 29, 2024

There are some difficulties in writing application fingerprints. This is a non-open source application and there are only four tags in two official hubs.

https://hub.docker.com/r/helpsystems/goanywhere-mft
https://hub.docker.com/r/fortrallc/goanywhere-mft

@SuperX-SIR
Copy link
Contributor Author

There are some difficulties in writing application fingerprints. This is a non-open source application and there are only four tags in two official hubs.

https://hub.docker.com/r/helpsystems/goanywhere-mft https://hub.docker.com/r/fortrallc/goanywhere-mft

get login html will response with title version

图片

@tooryx
Copy link
Member

tooryx commented Sep 30, 2024

Hi @SuperX-SIR,

Then you can continue with the development of the RCE.

~tooryx

@tooryx tooryx added the Contributor main The main issue a contributor is working on (top of the contribution queue). label Sep 30, 2024
@SuperX-SIR
Copy link
Contributor Author

Add instructions to create the test environment google/security-testbeds#90

@tooryx tooryx linked a pull request Oct 23, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor main The main issue a contributor is working on (top of the contribution queue).
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants