Sploitus

Exploit for Code Injection in Elastic Kibana

githubexploit ยท 2021-08-24

Exploit Code

README30 lines
## https://sploitus.com/exploit?id=DCFE3B87-DB52-53A3-8ED6-D8E4E7F8310E
# CVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer
https://nvd.nist.gov/vuln/detail/CVE-2019-7609

# CVE-2019-7609
์œ„ ์ทจ์•ฝ์ ์€ Kibana์—์„œ ๋ฐœ๊ฒฌ๋œ Prototype Pollution ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜๋ฉด DoS๋‚˜ RCE ๊ณต๊ฒฉ์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 

# ํŠน์ง•
* Node์—์„œ ์ œ๊ณตํ•˜๊ณ  ์žˆ๋Š” debugging ์˜ต์…˜์„ ์ถ”๊ฐ€ํ•˜์˜€์Šต๋‹ˆ๋‹ค.
* Chrome://inspect๋กœ ๋“ค์–ด๊ฐ€ ๋””๋ฒ„๊น…์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 

# ์„ค์น˜ ๋ฐ ์‹คํ–‰ ์ˆœ์„œ

#### 1. Kibana ์„ค์น˜
์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•  ๋•Œ, docker-compose.yml ํŒŒ์ผ์—์„œ ํฌํŠธํฌ์›Œ๋”ฉ์„ ์ง„ํ–‰ํ•ด์ฃผ์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค. 
 $ docker-compose up  

#### 2. ๋””๋ฒ„๊น… ์—ฐ๊ฒฐ 


# ์ถœ์ฒ˜
https://github.com/hekadan/CVE-2019-7609 
https://www.cnblogs.com/anyun/p/8458476.html 
https://slides.com/securitymb/prototype-pollution-in-kibana/#/41 

# ์ฃผ์˜ ์‚ฌํ•ญ
#### ์œ„ ์ทจ์•ฝ์ ์„ ๋ถˆ๋ฒ•์œผ๋กœ ์•…์šฉํ•  ์‹œ, ๋ฒ•์  ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
#### If you illegally exploit the above vulnerabilities, you will not be held liable.
#### docker ๋ฒ„์ „์„ ์ตœ์‹ ํ™” ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.