ZeroHour
Security Affairspublished ()ingested @securityaffairs

US DoD discloses details about critical and high severity flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0192
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request.

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

NVD description · AI analysis pending
9.878%
  • apache solr
  • apache storage automation store
CVE-2019-0193
Code Injection RCE in Apache Solr DataImportHandler (DIH)

CVE-2019-0193 is a code injection flaw (CWE-94) in the DataImportHandler (DIH), an optional but popular Apache Solr module used to pull in data from databases and other sources. The DIH configuration can be supplied at request time via the 'dataConfig' parameter (used by the DIH admin screen's debug mode), and because such configs can embed scripts, a crafted parameter allows arbitrary code execution. A successful attacker gains remote code execution within the Solr process (C:H/I:H/A:H); the 7.2 CVSS reflects that high-privilege access to the Solr admin/DIH interface is normally required, though internet-exposed instances without authentication remove that barrier. Any Solr deployment using DIH on versions before 8.2.0, when the 'enable.dih.dataConfigParam' opt-in Java system property was introduced, is affected, including Solr packages shipped with Debian Linux. Exploitation is confirmed in the wild (added to the CISA KEV on 2021-12-10), EPSS assigns an 83.5% 30-day exploitation probability (100th percentile), and no public PoC is catalogued.

Do: Upgrade Apache Solr to 8.2.0 or later, or apply vendor updates per the CISA KEV required action; if upgrading is not immediately possible, restrict access to the Solr admin UI and the dataimport handler and leave the 'enable.dih.dataConfigParam' property disabled unless needed. Check access logs for requests to the dataimport handler containing a 'dataConfig' parameter as an indicator of probing or exploitation. Ransomware linkage is listed as unknown, so treat any exposed instance as a potential foothold.

7.284% KEV
  • Apache Solr Versions prior to 8.2.0 where the DataImportHandler is in use (8.2.0 introduced the enable.dih.dataConfigParam opt-in flag; the data does not enumerate earlier
  • Debian Linux
large≈10,000–40,000 internet-exposed Solr instances, plus a larger uncounted population of internal and embedded deployments
Full article386 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 04, 2020

The U.S. Department of Defense has disclosed the details about four critical and high severity vulnerabilities in its infrastructure.

The U.S. Department of Defense has disclosed details of four vulnerabilities in its infrastructure, two high severity rating issues and other two critical flaws.

The vulnerabilities could be exploited by threat actors to hijack a subdomain, execute arbitrary code remotely, or view files on the vulnerable system.

The vulnerabilities were reported in August and July through the Department’s bug bounty program operated via HackerOne.

One of the critical issues is a subdomain takeover due to an unclaimed Amazon S3 bucket.

The ethical hacker chron0x who reported the flaw discovered that the subdomain was referencing an Amazon S3 bucket in the US East region that did no longer exists. The hackers claimed this bucket and successfully took over the subdomain.

“This is extremely vulnerable to attacks as a malicious user could create any web page with any content and host it on the deployedmedicine.com domain.” reads the advisory. “This would allow them to post malicious content which would be mistaken for a valid site. They could:

  • XSS
  • Phishing
  • Bypass domain security
  • Steal sensitive user data, cookies, etc.”

An attacker could exploit the issue to target visitors of the website with phishing and cross-site scripting attacks. 

The second critical flaw is a remote code execution on a DoD server running Apache Solr that had been left unpatched since August 2019.

The vulnerability was reported by the ethical hacker Hzllaga on August 19.

The expert discovered that the server was vulnerable to CVE-2019-0192 and CVE-2019-0193, he successfully exploited CVE-2019-0193 and successfully remotely executed arbitrary code.

One of the high-severity issues disclosed by the Department is an unpatched read-only path traversal in a Cisco product used by the agency. The issue could be exploited to access arbitrary sensitive files on the system.

The second high-severity issue is a code injection on a DoD host that may lead to arbitrary code execution. The flaw was reported by e3xpl0it from Positive Technologies.

The DoD quickly addressed all the vulnerabilities.

Since the DoD launched a bug bounty program on HackerOne in November 2016, it addressed a total of 9555 security issues.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, U.S. Department of Defense)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/107905/hacking/u-s-department-of-defense-flaws.html