ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Equifax breach happened because of a missed patch

mediumVulnerabilityimportance 35CVE-2017-5638

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-5638
Unauthenticated RCE in Apache Struts Jakarta Multipart parser

CVE-2017-5638 is an improper input validation flaw (CWE-20) in the Jakarta Multipart parser of Apache Struts, in which the parser mishandles the Content-Type value of a file upload and allows malicious upload leading to remote code execution. It is triggered remotely without authentication by sending a crafted Content-Type header in a multipart request to a Struts endpoint; no valid upload or credentials are required. A successful attacker gains code execution in the security context of the application server, which typically enables host compromise, data theft, or ransomware deployment. Any organization running Apache Struts applications that use the Jakarta Multipart parser is affected; the provided data specifies only "Apache Struts" and gives no version ranges. Exploitation is confirmed in the wild: the flaw is listed in CISA KEV (added 2021-11-03) with known ransomware use, EPSS assigns it roughly a 100% exploitation probability (100th percentile), and no public PoC is catalogued in the source data.

Do: Apply updates per vendor instructions: upgrade Apache Struts to the releases that fix this flaw (2.3.32 / 2.5.10.1 or later, per Apache advisory S2-045), and check for Struts jars bundled inside application packages and vendor appliances. Prioritize internet-facing apps, and as an interim mitigation validate or filter the Content-Type header on multipart requests. Because exploitation is in the wild and ransomware use is known, also review web and application server logs for evidence of successful compromise.

9.8100% KEV ransomware PoC ×10
  • Apache Struts
masslikely hundreds of thousands of deployments (tens of thousands of Struts hosts were internet-exposed in public scans)
Full article346 words · extracted from helpnetsecurity.com · click to collapse

The attackers who breached Equifax managed to do so by exploiting a vulnerability in its US website, the company has finally confirmed. The vulnerability – CVE-2017-5638 – affects Apache Struts 2.

Equifax breach patch

A failure to implement available patch

CVE-2017-5638 was flagged in March 2017. It was discovered and reported by Chinese developer Nike Zheng.

It was quickly patched by the Apache Struts team, but the disclosure was followed by active attacks via two very reliable exploits that had already been published online.

The Equifax hack was traced back to mid-May, meaning that the site’s administrators obviously failed to implement the security update for over nine weeks. And then, the company failed to spot the intrusion until July.

Following initial reports that an Apache Struts flaw was how the attackers got in, Apache Struts VP René Gielen explained their efforts to keep on top of things by quickly patching discovered and reported vulnerabilities.

He also advised businesses and individuals utilizing Apache Struts to keep track of announcements affecting the product, and to establish a process to quickly roll out a security fix release of their software product once the framework has been updated.

Other recent changes

In this latest progress update, Equifax has reiterated that affected customers who take advantage of the free Trusted ID credit monitoring service membership offered by the company will not be forfeiting their right to join a class action suit against the company.

The company has also noted that due to the high volume of security freeze requests, they experienced temporary technical difficulties that forced their system offline for approximately an hour on Wednesday.

More than likely, this had something to do with the announcement that the company has waived credit-freeze fees ($10 per freeze) for those affected by the breach, but just until November 21.

In addition to all this, the company has changed the way it generates the PINs when a consumer initiates the Equifax security freeze. The PIN is now randomly generated, instead of being easily guessable combination of the date and time when the customer initiated the procedure.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/09/14/equifax-breach-patch/