Advisories

Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cache

Go Back
severity
high
date
Affecting
  • nuclei >= 3.7.0, < 3.11.1

CWE
  • CWE-347 Improper Verification of Cryptographic Signature
CVSS
7.0
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
George Chen
Description
Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modification time to bypass signature checks and execute arbitrary operating system commands.

Ready to get Started?

Explore VulnCheck, a next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence to help you prioritize and remediate vulnerabilities that matter.
  • Vulnerability Prioritization
    Prioritize vulnerabilities that matter based on the threat landscape and defer vulnerabilities that don't.
  • Early Warning System
    Real-time alerting of changes in the vulnerability landscape so that you can take action before the attacks start.