[Japanese]

JVNDB-2023-000073

GBrowse vulnerable to unrestricted upload of files with dangerous types

Overview

GBrowse provided by Generic Model Organism Database Project is a web-based genome browser. GBrowse allows the users to upload their own data in several file formats (see "GBrowse User Uploads").
The affected versions of GBrowse accept files with any formats uploaded (CWE-434), and place them in the area accessible through unauthenticated web requests.

The reporter states that attacks exploiting this vulnerability have been observed.

Cyber Defense Institute, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.3 (Medium) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: None
  • Integrity Impact: Low
  • Availability Impact: None
CVSS V2 Severity:
Base Metrics 5.0 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Low
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


Generic Model Organism Database Project
  • GBrowse

The reporter verifies that version 1.70 is vulnerable to this issue, and that version 2.56 restricts uploading non-GFF formatted files. This indicates that the file validation mechanism may have been implemented since version 2.x.
Impact

Anyone who can upload files through the product may execute arbitrary code on the server.
Solution

[Stop using the product and Switch to the successor]
The developer states that GBrowse is no longer supported and recommends using the successor product JBrowse2.
Vendor Information

Generic Model Organism Database Project
  • Generic Model Organism Database Project : GBrowse
  • Generic Model Organism Database Project : JBrowse
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2023-32637
References

  1. JVN : JVN#35897618
  2. National Vulnerability Database (NVD) : CVE-2023-32637
Revision History

  • [2023/07/21]
      Web page was published
  • [2024/04/12]
      References : Content was added