[Eclipse Theia] Arbitrary code execution via untrusted git repository configuration
<!-- This ticket is confidential. --> <!-- ############################# Do not remove the lines above ############################# --> # CVE Reservation Request <!-- There's help in the Eclipse Foundation Project Handbook https://www.eclipse.org/projects/handbook/#vulnerability-cve Note that this issue is configured (see the quick actions at the bottom) to be created as confidential. Note that a vulnerability does not need to actually be resolved before it is reported and that these reports can be revised as needed (reopen the issue to request changes). If you do not know how to fill certain fields, mark that in the comment and we will help you. You can delete the comments (or not). --> The Eclipse Foundation is a [Common Vulnerabilities and Exposures](https://cve.mitre.org/) (CVE) Numbering Authority. Creating this ticket initiates **reservation** of a CVE ID for the documented vulnerability. The reserved CVE ID will be posted in a comment below, and kept **confidential** until explicit publication request. > [!note] > To request CVE *publication*, please open a [CVE publication](https://gitlab.eclipse.org/security/cve-assignment/-/issues/new?issuable_template=CVE%20Publication%20Request&issue[confidential]=true) ticket. Please fill in the fields below to draft the CVE record. --- <!-- Required. Specify the project's name (e.g., "Eclipse Dash") and Eclipse Foundation ID, e.g., "technology.dash". --> ## CVE record information **Project name:** Eclipse Theia **Project id:** ecd.theia <!-- Required (for publication). Specify the version range as precisely as possible, e.g., "[3.0, 3.5.1]" or "[3.0, 3.5.1)". Note that using the standard range notion, square brackets are inclusive (i.e., that version is included in the range), and round brakets are exclusive (the vulnerability affects all versions up to but not including the named version). Multiple ranges can be provided. --> **Versions affected:** [0, 1.70.0) <!-- Required (for publication). The Common Weakness Enumeration (CWE) code comes from here: https://cwe.mitre.org/, e.g., "CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')". Multiple codes can be provided. --> **Common Weakness Enumeration (CWE):** - [CWE-829: Inclusion of Functionality from Untrusted Control Sphere](https://cwe.mitre.org/data/definitions/829.html) - [CWE-15: External Control of System or Configuration Setting](https://cwe.mitre.org/data/definitions/15.html) <!-- Optional. The Common Attack Pattern Enumerations and Classifications (CAPEC) code comes from here: https://capec.mitre.org/, e.g., "CAPEC-63: Cross-Site Scripting (XSS)". Multiple codes can be provided. --> **Common Attack Pattern Enumerations and Classifications (CAPEC):** - [CAPEC-176: Configuration/Environment Manipulation](https://capec.mitre.org/data/definitions/176.html) - [CAPEC-549: Local Execution of Code](https://capec.mitre.org/data/definitions/549.html) <!-- Optional. Provide a Common Vulnerability Scoring System (CVSS). Note that if you do not provide this, then some agencies (e.g. NIST) will compute it on the project's behalf. Please be sure to include the CVSS version number, e.g., "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H". There's help here: https://www.first.org/cvss/calculator/4.0 --> **Common Vulnerability Scoring System:** [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) <!-- Required (for publication). The summary should start with the name of the project, e.g., "Eclipse Vert.x", then a description of the affected versions, followed by a description of the problem. The summary should be concise. For example, "In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response." --> **Summary:** In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own `@theia/git` extension and the builtin VS Code `git` extension run git commands such as `git status` as soon as a repository is detected. Since git honors repository-local configuration, a folder containing an attacker-controlled `.git/config` with `core.fsmonitor` (or a comparable hook-like setting) causes the configured command to be executed. The configuration can be delivered by burying a bare repository inside a regular repository (OVE-20210718-0001), so cloning an attacker-supplied repository and opening it in a Theia-based application is sufficient to execute arbitrary commands with the privileges of the user, without any confirmation prompt. As of 1.70.0, plugins that declare `capabilities.untrustedWorkspaces.supported: false`, which includes the builtin git extension, are no longer loaded or activated in an untrusted workspace, and the deprecated `@theia/git` extension has been removed, so no git command is executed against an untrusted folder. <!-- Required (for publication). Include a link to the issue (e.g., GitHub Security Advisory) that's being used to track/resolve the issue. Other links that provide more information can be provided. For example, you may later publish the link to the fix commit. --> **Links:** - Workspace trust dialog and management: https://github.com/eclipse-theia/theia/pull/16809 - Workspace trust enforcement in the extension/plugin system: https://github.com/eclipse-theia/theia/pull/17098 - Removal of the deprecated `@theia/git` extension: https://github.com/eclipse-theia/theia/pull/17148 - Original report: https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/175 <!-- Optional. Add the name or pseudonym of the person who has reported the issue. --> **Credits:** - Sudhanshu (https://gitlab.eclipse.org/sudi)
issue

Copyright © Eclipse Foundation AISBL. All rights reserved.     Privacy Policy | Terms of Use | Copyright Agent