Nuclei flaw lets malicious templates bypass signature verification
ID: 09165134-9d44-5602-862f-992e1b218bb7
STIX ID: report--09165134-9d44-5602-862f-992e1b218bb7
Feed Name: Bleeping Computer
Threat Score
A signature verification bypass (CVE-2024-43405) in the Nuclei scanner permits attackers to inject malicious code into signed YAML templates by exploiting newline interpretation differences between Go’s regex check and the YAML parser and by adding extra "# digest:" lines; ProjectDiscovery released a fix in Nuclei v3.3.2 and users are advised to update and run Nuclei in isolated environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
