Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Template for CVE-2022-21449 #4216

Closed
righettod opened this issue Apr 21, 2022 · 2 comments
Closed

Template for CVE-2022-21449 #4216

righettod opened this issue Apr 21, 2022 · 2 comments
Labels
Type: Enhancement Most issues will probably ask for additions or changes.

Comments

@righettod
Copy link
Contributor

Please describe your feature request:

I created this template to detect exposure to CVE-2022-21449.

Do you consider that this one is suitable for the collection of nuclei templates?

If yes, I will submit a PR 😃

Describe the use case of this feature:

The objective of this template is to detect couple of JWT API + JDK prone to the vulnerability represented by the CVE:

image

Thank you very much in advance 😃

@righettod righettod added the Type: Enhancement Most issues will probably ask for additions or changes. label Apr 21, 2022
@ehsandeep
Copy link
Member

@righettod thank you for sharing this, but not sure how we can fit this into the template as the matcher are mostly configured for specific vulnerability vs in this case we are looking for 200 status code which will be true for many other unrelated web server as well.

@righettod
Copy link
Contributor Author

@ehsandeep Yes, you have 100% right. It was a first proposal and I will refactor it to decrease the probability of false-positive.

I will come back with a new proposal once it will be ready and more accurate 😃

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Type: Enhancement Most issues will probably ask for additions or changes.
Projects
None yet
Development

No branches or pull requests

2 participants