Breaking the Chain: Wiz Uncovers a Signature Verification Bypass in Nuclei, the Popular Vulnerability Scanner (CVE-2024-43405)
ID: e3b5e713-0926-5fa9-9d78-7c8b4b930dee
STIX ID: report--e3b5e713-0926-5fa9-9d78-7c8b4b930dee
Feed Name: Wiz Blog
Wiz disclosed CVE-2024-43405, a high-severity signature verification bypass in the Nuclei template engine that allows attackers to inject and execute unverified template content. The issue stems from inconsistent handling of line breaks and dual parsing (regex for signature extraction vs YAML for execution), enabling attackers to craft templates that bypass verification (using carriage returns) and execute commands via the `code` protocol. The report includes proof-of-concept templates, a technical walkthrough of the regex/YAML mismatch, an exploit chaining explanation, and responsible disclosure timeline; remediation is to upgrade to Nuclei 3.3.2+ and run templates in isolated/sandboxed environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
