目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2023-3128 PoC — Grafana 安全漏洞

来源
关联漏洞
标题: Grafana 安全漏洞 (CVE-2023-3128)
Description:Grafana是Grafana开源的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana存在安全漏洞,该漏洞源于当使用多租户应用程序配置Azure AD OAuth时,会导致帐户接管和身份验证绕过。
介绍
# CVE-2023-3128

To check if a domain is vulnerable to CVE-2023-3128, which involves an authentication bypass in Grafana due to Azure AD email claim validation, you can use the following Python script:

-------------------
#!/usr/bin/env python3
import requests
import argparse

def check_cve_2023_3128(target_url, verbose=False):
    """Check for CVE-2023-3128 vulnerability"""
    session = requests.Session()
    
    # Step 1: Verify Azure AD SSO configuration
    try:
        response = session.get(
            f"{target_url}/login",
            allow_redirects=False,
            timeout=10
        )
        azure_ad_configured = any(
            "azuread" in location.lower() 
            for location in response.headers.get('Location', '')
        )
        
        if verbose:
            print(f"[*] Azure AD SSO configured: {azure_ad_configured}")
            
    except requests.RequestException as e:
        if verbose:
            print(f"[!] Connection error: {str(e)}")
        return False

    # Step 2: Attempt authentication bypass (spoofing)
    # Note: This requires creating an Azure AD account with the same email as a target Grafana user.
    #       This step is not automated due to ethical and legal considerations.
    if azure_ad_configured:
        if verbose:
            print("[*] Azure AD SSO is enabled. Vulnerability may be exploitable via email spoofing.")
        return True
    else:
        if verbose:
            print("[-] Azure AD SSO not detected or not vulnerable.")
        return False

def main():
    parser = argparse.ArgumentParser(description='CVE-2023-3128 Scanner')
    parser.add_argument('url', help='Target URL (e.g., https://example.com)')
    parser.add_argument('-v', '--verbose', action='store_true', help='Enable verbose output')
    args = parser.parse_args()

    if check_cve_2023_3128(args.url, verbose=args.verbose):
        print(f"\nTarget {args.url} may be vulnerable to CVE-2023-3128.")
        print("Recommendation: Update Grafana to version ≥9.5.5 and ensure Azure AD OAuth is properly configured.")
    else:
        print(f"\nTarget {args.url} does not appear to be vulnerable to CVE-2023-3128.")

if __name__ == "__main__":
    main()
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →