Posted by disclosure via Fulldisclosure on Oct 060day Rubbish Research Team is publicly disclosing a vulnerability in
StreamSets Transformer, the Spark-engine data-pipeline platform from
StreamSets Inc. (subsequently acquired by IBM), verified on version 3.17.0
analysed from the official container image.
Type: failing-open authentication plus un-sandboxed code injection. On the
web tier, CWE-306 and CWE-1188 with CWE-285 on the authorisation side: when
the effective http.authentication value...
Full Disclosure
mailing list archives
0day Rubbish Research Team is publicly disclosing a vulnerability in StreamSets Transformer, the Spark-engine data-pipeline platform from StreamSets Inc. (subsequently acquired by IBM), verified on version 3.17.0 analysed from the official container image. Type: failing-open authentication plus un-sandboxed code injection. On the web tier, CWE-306 and CWE-1188 with CWE-285 on the authorisation side: when the effective http.authentication value resolves to none, the embedded servlet container installs no authentication handler at all, and the same state with DPM disabled registers a filter on every path that makes every role check pass and presents a synthesised admin principal. At the sink, CWE-94: the REST pipeline API accepts an attacker-chosen pipeline whose ScalaDTransform code field, an unconstrained text configuration entry, is compiled with the full Scala compiler and executed inside the service JVM, which runs as uid 0. The research records exactly three absences on that path: no SecurityManager, no sandbox and no API allowlist. Scoring. Dual-scored, with the primary reading named first: - PRIMARY, as distributed, 8.1 High, vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Attack complexity is high because success depends on a target state the attacker does not control: the shipped properties file sets aster, so the anonymous state is reached by operator choice or by loss of the property. - CONDITIONAL, 9.8 Critical, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, for deployments whose effective mode does resolve to none, including the verified instance, where the chain completed deterministically. This is the deployment-conditional reading and is not the factory-state rating. Impact: anonymous code execution as uid 0 inside the container on the first command, with no escalation step; unrestricted read of every stored pipeline definition including connection configuration, of the product property files and of the container filesystem; arbitrary modification of product state; and availability impact on an engine that sits between upstream sources and downstream warehouses. No sandbox was bypassed, because none exists on the compile-and-run path. Verification boundary, stated plainly. Verified end to end over plain HTTP against a live instance of the official container image, three independent runs, each leaving a per-run unique root-owned marker file; the identity command returned uid 0 inside the container and command output was recovered out of band from the container filesystem. No instance was exercised at its shipped property value, so no bypass of the authenticated configuration is claimed; the property-loss fallback is established from decompiled code rather than a live experiment; container root was reached with no escape attempted or claimed; only version 3.17.0 was tested. The shipped proof-of-concept takes every target detail as a parameter and includes a probe mode that tests the precondition without attacking. Full technical analysis and a reproducible proof-of-concept: https://0day-rubbish.com/blog/streamsets-transformer-auth-none-scaladtransform-code-execution Project archive (ongoing disclosure series): https://github.com/Exploit-Garbage/0day-Rubbish The vendor has been notified through the product-security intake the vendor publishes for this product line. No vulnerability identifier has been assigned to this finding yet. -- 0day Rubbish Research Team disclosure () 0day-rubbish com https://0day-rubbish.com _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/