ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Apache fixed a critical SQL Injection in Apache Traffic Control

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-17530
Forced OGNL Evaluation RCE in Apache Struts 2.0.0-2.5.25

CVE-2020-17530 is a critical (CVSS 9.8) expression-language injection flaw (CWE-917) in Apache Struts 2, in which the framework forces evaluation of OGNL expressions contained in raw, attacker-supplied user input placed into certain tag attributes. An attacker triggers it by sending crafted input (for example OGNL expressions such as %{...}) that an application passes unsanitized into a tag attribute, causing Struts to evaluate the payload as code; the network attack vector requires no authentication or user interaction. Successful exploitation yields remote code execution in the context of the hosting application server, with high impact on confidentiality, integrity, and availability. All Apache Struts 2 releases from 2.0.0 through 2.5.25 are affected, and multiple Oracle products that bundle Struts - Business Intelligence, Communications Diameter Intelligence Hub, Communications Policy Management, Communications Pricing Design Center, Financial Services Data Integration Hub, Hospitality OPERA 5, and MySQL Enterprise Monitor - are also impacted. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 95.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged in this data.

Do: Upgrade Apache Struts to 2.5.26 or later (or the corresponding legacy-branch fix, 2.3.68) per vendor instructions, and apply the relevant Oracle Critical Patch Updates for the bundled products listed above. Audit custom Struts applications for places where raw user input flows into tag attributes, since exposure depends on application usage, and review internet-facing Struts servers for indicators of OGNL injection exploitation. Because the flaw is on the CISA KEV list, apply the required vendor updates within the mandated remediation timeframe.

9.896% KEV
  • Apache Struts 2 2.0.0 through 2.5.25
  • Oracle Business Intelligence
  • Oracle Communications Diameter Intelligence Hub
  • +5 more
masson the order of 10^5-10^6 internet-exposed Apache Struts deployments, plus an unquantified embedded base in Oracle products
CVE-2024-45387
Authenticated SQL Injection in Apache Traffic Control Traffic Ops

CVE-2024-45387 is an SQL injection flaw in Traffic Ops, the API component of the Apache Traffic Control CDN management platform, affecting version 8.0.0 per the Apache advisory. It is triggered when a user who already holds one of the "admin", "federation", "operations", "portal", or "steering" roles sends a specially crafted PUT request to the Traffic Ops API. Successful injection lets the attacker execute arbitrary SQL against the Traffic Ops database, allowing them to read, modify, or corrupt stored data, consistent with the high confidentiality, integrity, and availability ratings in the 8.8 CVSS score. Any operator running an affected Traffic Ops deployment is exposed, though exploitation requires an authenticated privileged account. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS places this flaw in the 99th percentile with roughly a 41.5% probability of exploitation within 30 days, so patching is urgent.

Do: Upgrade Traffic Ops to Apache Traffic Control 8.0.2 or later as recommended by the advisory. In the meantime, restrict API access to trusted networks and review accounts holding the admin, federation, operations, portal, and steering roles, since any of them can trigger the injection via crafted PUT requests. Check Traffic Ops and database logs for unexpected or anomalous SQL from API activity, and watch for public exploits given the elevated EPSS score.

8.842%
  • Apache Traffic Control (Traffic Ops) 8.0.0 and earlier per the advisory (fixed in 8.0.2)
nichelikely hundreds to low thousands of Traffic Ops deployments worldwide
Full article263 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 26, 2024

Apache Software Foundation (ASF) addressed a critical SQL Injection vulnerability, tracked as CVE-2024-45387, in Apache Traffic Control.

The Apache Software Foundation (ASF) released security updates to address a critical security vulnerability, tracked as CVE-2024-45387 (CVSS score 9.9), in Traffic Control.

Traffic Control allows operators to set up a Content Delivery Network to quickly and efficiently deliver content to their users. Traffic Control is a highly distributed, scalable and redundant solution meeting the needs of operators from small to large.

The flaw is an SQL injection vulnerability in Traffic Control (<= 8.0.1, >= 8.0.0), it allows privileged users to execute arbitrary SQL commands.

“An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role “admin”, “federation”, “operations”, “portal”, or “steering” to execute arbitrary SQL against the database by sending a specially-crafted PUT request.” reads the advisory. “Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.”

Traffic Control 7.0.0 before 8.0.0 are not affected by this vulnerability.

The researchers Yuan Luo from Tencent YunDing Security Lab reported the vulnerability.

Early this month, The Apache Software Foundation released a security update to address a “possible remote code execution” flaw in Struts 2 that is related to the OGNL technology. 

The remote code execution flaw, tracked as CVE-2020-17530, resides in forced OGNL evaluation when evaluated on raw user input in tag attributes.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Traffic Control)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172307/security/apache-traffic-control-critical-flaw.html