关联漏洞
标题:Solar appScreener 代码问题漏洞 (CVE-2022-24449)Description:Solar appScreener是Solar appScreener公司的一种静态应用程序安全测试 (SAST) 工具。用于检测二进制和源代码中的漏洞和后门。 Solar appScreener 3.10.4 及之前版本存在安全漏洞,该漏洞源于当没有有效许可证时,允许通过精心制作的 XML 文档进行 XXE 和 SSRF 攻击。
Description
Solar Appscreener XXE
介绍
# CVE-2022-24449
Solar Appscreener XXE
[Suggested description]
An issue was found in Solar AppScreener SAST tool through 3.10.4. An unauthorized actor, may exploit effected hosts where vulnerable version is installed, by uploading specially crafted XML files on hosts, which has an expired or non-installed license. The lowest approved impact is XXE-SSRF.
------------------------------------------
[Additional Information]
Fixed in >3.10.4
------------------------------------------
[VulnerabilityType Other]
CWE-611: Improper Restriction of XML External Entity Reference
------------------------------------------
[Vendor of Product]
SOLAR SECURITY LLC (https://en.rt-solar.ru/)
------------------------------------------
[Affected Product Code Base]
Affected version: Solar Appscreener 3.10.4
------------------------------------------
[Affected Component]
License update mechanism
------------------------------------------
[Attack Type]
Remote
------------------------------------------
[Impact Code execution]
true
------------------------------------------
[Impact Denial of Service]
true
------------------------------------------
[Impact Escalation of Privileges]
true
------------------------------------------
[Impact Information Disclosure]
true
------------------------------------------
[Attack Vectors]
An attacker able to upload specially crafted XML file via license update function
------------------------------------------
[Discoverer]
Dmitry Kuramin (Jet Infosystems, jet.su)
------------------------------------------
[Reference]
https://jet.su
文件快照
[4.0K] /data/pocs/a2123a60fe49bccf481184355049beded089ea34
├── [ 11M] 20220126_160130.mp4
├── [1.5K] README.md
├── [318K] xxe1.png
└── [249K] xxe2.png
0 directories, 4 files
备注
1. 建议优先通过来源进行访问。
2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →