Skip to content

Apache ShardingSphere-Agent Deserialization of Untrusted Data vulnerability

High severity GitHub Reviewed Published Jul 19, 2023 to the GitHub Advisory Database • Updated Nov 7, 2023

Package

maven org.apache.shardingsphere:shardingsphere (Maven)

Affected versions

<= 5.3.2

Patched versions

5.4.0

Description

Deserialization of Untrusted Data vulnerability in Apache ShardingSphere-Agent, which allows attackers to execute arbitrary code by constructing a special YAML configuration file.

The attacker needs to have permission to modify the ShardingSphere Agent YAML configuration file on the target machine, and the target machine can access the URL with the arbitrary code JAR.
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. When the ShardingSphere JVM process starts and uses the ShardingSphere-Agent, the arbitrary code specified by the attacker will be executed during the deserialization of the YAML configuration file by the Agent.

This issue affects ShardingSphere-Agent: through 5.3.2. This vulnerability is fixed in Apache ShardingSphere 5.4.0.

References

Published by the National Vulnerability Database Jul 19, 2023
Published to the GitHub Advisory Database Jul 19, 2023
Reviewed Jul 20, 2023
Last updated Nov 7, 2023

Severity

High
8.8
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

CVE-2023-28754

GHSA ID

GHSA-3cxh-xp3g-jxjm

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.