CVE-2020-36911
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Cobbr | Covenant | — | 0.1.3 ≤ 0.5 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-798 | cna | Use of Hard-coded Credentials |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 9.3 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
References (7)
- ExploitDB-51141 https://www.exploit-db.com/exploits/51141
- Vendor Homepage https://cobbr.io/Covenant.html
- Covenant GitHub Repository https://github.com/cobbr/Covenant
- Archived Researcher Blog https://web.archive.org/web/20201101052547/https://blog.null.farm/hunting-the-hunters
- Exploit Repository https://github.com/Zeop-CyberSec/covenant_rce/blob/master/covenant_jwt_rce.rb
- Archived Maintainer Patch Announcement https://web.archive.org/web/20201013165001/https://twitter.com/cobbr_io/status/1316058367161401344
- VulnCheck Advisory: Covenant 0.5 - Remote Code Execution (RCE) https://www.vulncheck.com/advisories/covenant-remote-code-execution-rce