CSNC-2018-021 - Vert.x - HTTP Header Injection

Advisories <[email protected]> Wed, 13 Jun 2018 07:56:47 +0000
Newsgroups gmane.comp.security.bugtraq,gmane.comp.security.news.securitytracker
Message-ID <[email protected]>
#############################################################
#
# COMPASS SECURITY ADVISORY
# https://www.compass-security.com/research/advisories/
#
#############################################################
#
# Product:   Vert.x [1]
# CSNC ID:   CSNC-2018-021
# Subject:   HTTP Header Injection
# Risk:      Medium
# Effect:    Remotely exploitable
# Author:    Lukasz D. ([email protected])
# Date:      12.06.2018
#
#############################################################

Introduction:
-------------
Eclipse Vert.x is a tool-kit for building reactive applications on the JVM.
Vert.x can be used for simple network utilities, sophisticated modern web
applications, HTTP/REST microservices, high volume event processing
or a full-blown back-end message-bus applications. Vert.x is used by many
different companies from real-time gaming to banking and everything in betw=
een.

Vert.x does not filter carriage return and line feed characters from values=
 of
set HTTP response headers. This allows to manipulate values of the set HTTP
headers and to add arbitrary new headers. In particular, issuing a redirect=
ion
and manipulation of cookies set by the server is possible.

Affected:
---------
The following Vert.x versions are vulnerable:
- 3.0.0 - 3.5.1

Technical Description:
----------------------
The method putHeader(String name, String value) used to set new headers in =
the
HTTP response does not filter carriage return and line feed characters from
the header value. If a web application uses a user-provided parameter as
a value of the header, then it is possible for a user to add new HTTP heade=
rs
of his choice.

For example, a Vert.x-based web application may use the vulnerable method l=
ike
this: putHeader("User-Header", foo), where foo is the user-provided paramet=
er.

Then:
    Requesting /vulnerable?foo=3Dbar will add a header: "User-Header: bar".
    Requesting /vulnerable?foo=3Dbar%0D%0ASet-Cookie:%20mycookie=3Dhello wi=
ll add
        a header: "User-Header: bar" and additionally will set a new cookie
        with name "mycookie" and value "hello".

Workaround / Fix:
-----------------
It needs to be ensured that every header value which is set based on
a user-provided parameter does not contain carriage return and line feed
characters.

Timeline:
---------
2018-02-22:   Vulnerability discovered
2018-04-04:   Initial vendor notification
2018-04-04:   Initial vendor response
2018-06-04:   Patched version released
2018-06-13:   Public disclosure

References:
-----------
[1]: https://vertx.io/