Release the RAVEN: Exploiting the Cracks
ID: 7b4fd34e-2d29-5402-b25e-af8cc4cdcd31
STIX ID: report--7b4fd34e-2d29-5402-b25e-af8cc4cdcd31
Feed Name: LevelBlue SpiderLabs Blog
This post demonstrates the RAVEN tool's Elasticsearch-focused CVE catalog, automated version-based detection, and live exploit capabilities: root RCE via MVEL (CVE-2014-3120) and Groovy sandbox bypass (CVE-2015-1427), arbitrary file reads via snapshot and plugin directory traversal (CVE-2015-5531, CVE-2015-3337), and detection-only handling for API-key privilege escalation CVEs (CVE-2020-7009/7014); all results are captured from isolated lab environments and the tool also exposes a scripting module for authorized script execution assessment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
