Conflicts between URL mapping and URL based access control., (Mon, Nov 24th)
ID: 4f42a597-ced8-53f2-b788-fefc7ef87405
STIX ID: report--4f42a597-ced8-53f2-b788-fefc7ef87405
Feed Name: SANS ISC Diary
The SANS report details active scans and exploitation of template-injection vulnerabilities in Hitachi Vantara Pentaho Business Analytics (CVE-2022-43939 and CVE-2022-43769) where URL mapping/alias behavior (e.g., rewrites returning index.html or require.js) allows unauthenticated requests to reach vulnerable code paths and lead to remote code execution; the "Chicago Rapper" Rondo botnet is observed exploiting this vector. The author emphasizes reviewing URL remapping and access-control rules (and common regex mistakes) to prevent such bypasses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
