[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision)



0day Rubbish Research Team is publicly disclosing a vulnerability in 
RapidDeploy 5.2.2 (MidVision). The research is published and a proof-of-concept 
is available.

Pre-authentication RCE (arbitrary file write) (CVSS 9.8, pre-authentication)

MidVision RapidDeploy 5.2.2 ships a remote-agent template 
(midvision-remoting-server.xml) with host=0.0.0.0 and auth.servers commented 
out, making the JBoss Remoting layer network-reachable with no authentication. 
The invocation handler accepts any connection and performs arbitrary-path file 
writes on the target host; writing a cron entry yields root command execution. 
This is a shipped default-deployment template vulnerability. Dynamically 
verified.

Impact: Full compromise of CI/CD target hosts as root. The attacker can 
overwrite deployed artifacts, inject trojans into build and deploy pipelines, 
and take control of every managed server.

Advisory: 
https://0day-rubbish.com/blog/midvision-rapiddeploy-unauth-file-write-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/