CVE-2024-52588: Strapi allows Server-Side Request Forgery in Webhook function
Description In Strapi latest version, at function Settings -> Webhooks, the application allows us to input a URL in order to create a Webook connection. However, we can input into this field the local domains such as localhost, 127.0.0.1, 0.0.0.0,.... in order to make the Application fetching into the internal itself, which causes the vulnerability Server - Side Request Forgery (SSRF).
Payloads - http://127.0.0.1:80 -> The Port is not open - http://127.0.0.1:1337 -> The Port which Strapi is running on
Steps to Reproduce - First of all, let's input the URL http://127.0.0.1:80 into the URL field, and click "Save".
!CleanShot 2024-06-04 at 22 45 17@2x
- Next, use the "Trigger" function and use Burp Suite to capture the request / response
!CleanShot 2024-06-04 at 22 47 50@2x
- The server return request to http://127.0.0.1/ failed, reason: connect ECONNREFUSED 127.0.0.1:80, BECAUSE the Port 80 is not open, since we are running Strapi on Port 1337, let's change the URL we input above into http://127.0.0.1:1337
!CleanShot 2024-06-04 at 22 50 13@2x
- Continue to click the "Trigger" function, use Burp to capture the request / response
!CleanShot 2024-06-04 at 22 53 25@2x
- The server returns Method Not Allowed, which means that there actually is a Port 1337 running the machine.
PoC Here is the Poc Video, please check:
https://drive.google.com/file/d/1EvVp9lMpYnGLmUyr16gQ2RetI-GqYjV/view?usp=sharing
Impact
- If there is a real server running Strapi with many ports open, by using this SSRF vulnerability, the attacker can brute-force through all 65535 ports to know what ports are open.
Other sources
Strapi is an open-source content management system. Prior to version 4.25.2, inputting a local domain into the Webhooks URL field leads to the application fetching itself, resulting in a server side request forgery (SSRF). This issue has been patched in version 4.25.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52588?
CVE-2024-52588 is considered a medium severity vulnerability that allows local domains to be utilized for webhook connections.
How do I fix CVE-2024-52588?
To fix CVE-2024-52588, upgrade to the latest version of Strapi, specifically to version 4.25.2 or later.
What kind of systems are affected by CVE-2024-52588?
CVE-2024-52588 affects Strapi applications that allow webhook configurations without validation on the input URL.
What impact does CVE-2024-52588 have on Strapi applications?
CVE-2024-52588 may lead to unauthorized access and data exposure due to improper handling of local domain URLs in webhook settings.
Are there any workarounds for CVE-2024-52588?
While an explicit workaround is not documented, it is advisable to avoid using localhost or other local domains in webhook configurations until the vulnerability is patched.