CVE-2020-15146: Remote Code Execution in SyliusResourceBundle
Impact
Request parameters injected inside an expression evaluated by symfony/expression-language package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution.
The vulnerable versions include: <=1.3.13 || >=1.4.0 <=1.4.6 || >=1.5.0 <=1.5.1 || >=1.6.0 <=1.6.3.
Example
yaml syliusgrid: grids: foo: fields: bar: options: baz: "expr:service('sylius.repository.product').find($id)"
In this case, $id can be prepared in a way that calls other services.
If you visit /route?id="~service('doctrine').getManager().getConnection().executeQuery("DELETE FROM TABLE")~", it will result in a following expression expr:service('repository').find(""~service('doctrine').getManager().getConnection().executeQuery("DELETE FROM TABLE")~""), which will execute a query on the currently connected database.
To find a vulnerability in your application, look for any routing definition that uses request parameters inside expression language.
Patches
This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.
Workarounds
The fix requires adding addslashes in OptionsParser::parseOptionExpression to sanitize user input before evaluating it using the expression language.
php - return isstring($variable) ? sprintf('"%s"', $variable) : $variable; + return isstring($variable) ? sprintf('"%s"', addslashes($variable)) : $variable;
Acknowledgements
This security issue has been reported by Craig Blanchette (@isometriks), thanks a lot!
For more information
If you have any questions or comments about this advisory: Email us at security@sylius.com
Other sources
CVE-2020-15146: Remote Code Execution in OptionsParser while using request parameters inside expression language
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by symfony/expression-language package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15146?
CVE-2020-15146 is a vulnerability that allows remote code execution in OptionsParser while using request parameters inside express.
What is the severity of CVE-2020-15146?
The severity of CVE-2020-15146 is critical, with a CVSS score of 8.8.
Which software is affected by CVE-2020-15146?
SyliusResourceBundle versions 1.0.0 to 1.3.14, 1.4.0 to 1.4.7, 1.5.0 to 1.5.2, and 1.6.0 to 1.6.4 are affected by CVE-2020-15146.
How can an attacker exploit CVE-2020-15146?
An attacker can exploit CVE-2020-15146 by manipulating a request parameter to access any public service.
How can I fix CVE-2020-15146?
To fix CVE-2020-15146, update SyliusResourceBundle to versions 1.3.14, 1.4.7, 1.5.2, or 1.6.4.