Arbitrary classes can be loaded and instantiated using a HTTP PUT request to the /api/system/cluster_config/ endpoint.
Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loads the class using the class loader.
A request of the following form will output the content of the /etc/passwd file:
curl -u admin:<admin-password> -X PUT http://localhost:9000/api/system/cluster_config/java.io.File \
-H "Content-Type: application/json" \
-H "X-Requested-By: poc" \
-d '"/etc/passwd"'
To perform the request, authorization is required. Only users posessing the clusterconfigentry:create and clusterconfigentry:edit permissions are allowed to do so. These permissions are usually only granted to Admin users.
If a user with the appropriate permissions performs the request, arbitrary classes with 1-arg String constructors can be instantiated.
This will execute arbitrary code that is run during class instantiation.
In the specific use case of java.io.File, the behaviour of the internal web-server stack will lead to information exposure by including the entire file content in the response to the REST request.
Analysis provided by Fabian Yamaguchi - Whirly Labs (Pty) Ltd
{
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"github_reviewed_at": "2024-02-07T18:23:43Z",
"nvd_published_at": "2024-02-07T18:15:55Z",
"severity": "HIGH"
}