The Environment Variable That Ran Code — JavaScript Bug Hunt
Modelled on Shellshock (CVE-2014-6271, September 2014): Bash exported functions through environment variables, and its parser kept executing whatever…
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Parsing
- Modelled on: Shellshock · CVE-2014-6271
- Visible tests: a clean definition parses; trailing content makes the value invalid
- Reward: 50 XP for a complete fix
Briefing
Modelled on Shellshock (CVE-2014-6271, September 2014): Bash exported functions through environment variables, and its parser kept executing whatever followed the function definition. Any service that passed request data into the environment handed attackers command execution.
envparse.js has the same shape: it accepts a function definition in a variable and keeps everything after the closing brace.
Fix parseFunctionVar so trailing content after the definition is discarded and the variable rejected.
Bug report
BUG-SHELLSHOCK · Priority: Critical (RCE) · Reported by: security
parseFunctionVar(value) parses an exported function definition of the exact form "() { <body>; }" and must return { ok, body, trailing }:
- a clean definition returns { ok: true, body: "<body>", trailing: "" }
- a definition with ANYTHING after the closing brace is malformed: return { ok: false, body: "", trailing: "" } and parse nothing
- a value that is not a function definition returns { ok: false, ... } too
Observed: text after the closing brace is returned as trailing and the caller evaluates it.
Logs
[env] parsed HTTP_USER_AGENT trailing="echo pwned"
[env] trailing segment evaluated by the request handlerThe code as shipped
src/shell/envparse.js (editable)
// Parses an exported function definition out of an env var value.
exports.parseFunctionVar = function (value) {
var open = value.indexOf("() {");
if (open !== 0) return { ok: false, body: "", trailing: "" };
var close = value.indexOf("}", 4);
if (close === -1) return { ok: false, body: "", trailing: "" };
var body = value.substring(4, close).trim();
var trailing = value.substring(close + 1).trim();
return { ok: true, body: body, trailing: trailing };
};
Read-only context: src/shell/THREAT.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.