Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

some problems with weblogic_deserialize_asyncresponseservice.rb. #11835

Closed
C4o opened this issue May 11, 2019 · 1 comment
Closed

some problems with weblogic_deserialize_asyncresponseservice.rb. #11835

C4o opened this issue May 11, 2019 · 1 comment

Comments

@C4o
Copy link

C4o commented May 11, 2019

PoC in https://github.com/rapid7/metasploit-framework/blob/f89b0e848f559ad84555ffda8abcb9e228ed1bd3/modules/exploits/multi/misc/weblogic_deserialize_asyncresponseservice.rb is not a valid PoC for CVE-2019-2725, it's the PoC for CVE-2017-10271..Maybe you should refer to this,https://twitter.com/F5Labs/status/1120822404568244224..

@asoto-r7
Copy link
Contributor

asoto-r7 commented Jun 4, 2019

Thanks @C4o. It was difficult to judge, but we went ahead and updated the module. @wchen-r7 was gracious enough to do it while cleaning up some of the datastore options. He also added that tweet as a reference in the module.

Thanks again!

@asoto-r7 asoto-r7 closed this as completed Jun 4, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants