|
1895 | 1895 | } |
1896 | 1896 | } |
1897 | 1897 | }, |
| 1898 | + "crowdsecurity/vpatch-CVE-2022-3254": { |
| 1899 | + "author": "crowdsecurity", |
| 1900 | + "content": "IyMgYXV0b2dlbmVyYXRlZCBvbiAyMDI2LTAzLTMwIDEyOjM5OjE3Cm5hbWU6IGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIyLTMyNTQKZGVzY3JpcHRpb246ICdEZXRlY3RzIHVuYXV0aGVudGljYXRlZCBTUUwgaW5qZWN0aW9uIGluIEFXUCBDbGFzc2lmaWVkcyB2aWEgYWRtaW4tYWpheC5waHAgYWN0aW9uIGF3cGNwLWdldC1yZWdpb25zLW9wdGlvbnMuJwpydWxlczoKICAtIGFuZDoKICAgICAgLSB6b25lczoKICAgICAgICAgIC0gVVJJCiAgICAgICAgdHJhbnNmb3JtOgogICAgICAgICAgLSBsb3dlcmNhc2UKICAgICAgICAgIC0gdXJsZGVjb2RlCiAgICAgICAgbWF0Y2g6CiAgICAgICAgICB0eXBlOiBjb250YWlucwogICAgICAgICAgdmFsdWU6IC93cC1hZG1pbi9hZG1pbi1hamF4LnBocAogICAgICAtIHpvbmVzOgogICAgICAgICAgLSBBUkdTCiAgICAgICAgdmFyaWFibGVzOgogICAgICAgICAgLSBwYXJlbnQKICAgICAgICB0cmFuc2Zvcm06CiAgICAgICAgICAtIGxvd2VyY2FzZQogICAgICAgICAgLSB1cmxkZWNvZGUKICAgICAgICBtYXRjaDoKICAgICAgICAgIHR5cGU6IHJlZ2V4CiAgICAgICAgICB2YWx1ZTogIlteYS16MC05XSIKICAgICAgLSB6b25lczoKICAgICAgICAgIC0gQVJHUwogICAgICAgIHZhcmlhYmxlczoKICAgICAgICAgIC0gYWN0aW9uCiAgICAgICAgdHJhbnNmb3JtOgogICAgICAgICAgLSBsb3dlcmNhc2UKICAgICAgICAgIC0gdXJsZGVjb2RlCiAgICAgICAgbWF0Y2g6CiAgICAgICAgICB0eXBlOiBlcXVhbHMKICAgICAgICAgIHZhbHVlOiBhd3BjcC1nZXQtcmVnaW9ucy1vcHRpb25zCgpsYWJlbHM6CiAgdHlwZTogZXhwbG9pdAogIHNlcnZpY2U6IGh0dHAKICBjb25maWRlbmNlOiAzCiAgc3Bvb2ZhYmxlOiAwCiAgYmVoYXZpb3I6ICdodHRwOmV4cGxvaXQnCiAgbGFiZWw6ICdBV1AgQ2xhc3NpZmllZHMgLSBTUUxJJwogIGNsYXNzaWZpY2F0aW9uOgogICAgLSBjdmUuQ1ZFLTIwMjItMzI1NAogICAgLSBhdHRhY2suVDExOTAKICAgIC0gY3dlLkNXRS04OQo=", |
| 1901 | + "description": "Detects unauthenticated SQL injection in AWP Classifieds via admin-ajax.php action awpcp-get-regions-options.", |
| 1902 | + "labels": { |
| 1903 | + "behavior": "http:exploit", |
| 1904 | + "classification": [ |
| 1905 | + "cve.CVE-2022-3254", |
| 1906 | + "attack.T1190", |
| 1907 | + "cwe.CWE-89" |
| 1908 | + ], |
| 1909 | + "confidence": 3, |
| 1910 | + "label": "AWP Classifieds - SQLI", |
| 1911 | + "service": "http", |
| 1912 | + "spoofable": 0, |
| 1913 | + "type": "exploit" |
| 1914 | + }, |
| 1915 | + "path": "appsec-rules/crowdsecurity/vpatch-CVE-2022-3254.yaml", |
| 1916 | + "version": "0.1", |
| 1917 | + "versions": { |
| 1918 | + "0.1": { |
| 1919 | + "deprecated": false, |
| 1920 | + "digest": "373a3b40761e729e344e66253eb5fb8f0e2ce4e7e699b7f5ef45ef34063870f0" |
| 1921 | + } |
| 1922 | + } |
| 1923 | + }, |
1898 | 1924 | "crowdsecurity/vpatch-CVE-2022-35914": { |
1899 | 1925 | "author": "crowdsecurity", |
1900 | 1926 | "content": "bmFtZTogY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjItMzU5MTQKZGVzY3JpcHRpb246ICJHTFBJIFJDRSAoQ1ZFLTIwMjItMzU5MTQpIgpydWxlczoKICAtIGFuZDoKICAgIC0gem9uZXM6CiAgICAgIC0gVVJJCiAgICAgIHRyYW5zZm9ybToKICAgICAgLSBsb3dlcmNhc2UKICAgICAgbWF0Y2g6CiAgICAgICAgdHlwZTogZW5kc1dpdGgKICAgICAgICB2YWx1ZTogL3ZlbmRvci9odG1sYXdlZC9odG1sYXdlZC9odG1sYXdlZHRlc3QucGhwCgpsYWJlbHM6CiAgdHlwZTogZXhwbG9pdAogIHNlcnZpY2U6IGh0dHAKICBjb25maWRlbmNlOiAzCiAgc3Bvb2ZhYmxlOiAwCiAgYmVoYXZpb3I6ICJodHRwOmV4cGxvaXQiCiAgbGFiZWw6ICJHTFBJIC0gUkNFIgogIGNsYXNzaWZpY2F0aW9uOgogICAtIGN2ZS5DVkUtMjAyMi0zNTkxNAogICAtIGF0dGFjay5UMTU5NQogICAtIGF0dGFjay5UMTE5MAogICAtIGN3ZS5DV0UtNzQ=", |
|
2569 | 2595 | } |
2570 | 2596 | } |
2571 | 2597 | }, |
| 2598 | + "crowdsecurity/vpatch-CVE-2023-3197": { |
| 2599 | + "author": "crowdsecurity", |
| 2600 | + "content": "IyMgYXV0b2dlbmVyYXRlZCBvbiAyMDI2LTAzLTMwIDEyOjQ2OjUxCm5hbWU6IGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTMxOTcKZGVzY3JpcHRpb246ICdEZXRlY3RzIHVuYXV0aGVudGljYXRlZCBTUUwgaW5qZWN0aW9uIGluIFdvcmRQcmVzcyBNU3RvcmUgQVBJIHBsdWdpbiB2aWEgaWQgcGFyYW1ldGVyLicKcnVsZXM6CiAgLSBhbmQ6CiAgICAgIC0gem9uZXM6CiAgICAgICAgICAtIFVSSQogICAgICAgIHRyYW5zZm9ybToKICAgICAgICAgIC0gbG93ZXJjYXNlCiAgICAgICAgICAtIHVybGRlY29kZQogICAgICAgIG1hdGNoOgogICAgICAgICAgdHlwZTogY29udGFpbnMKICAgICAgICAgIHZhbHVlOiAvd3AtanNvbi9hcGkvZmx1dHRlcl9tdWx0aV92ZW5kb3IvcHJvZHVjdC1jYXRlZ29yaWVzCiAgICAgIC0gem9uZXM6CiAgICAgICAgICAtIEFSR1MKICAgICAgICB2YXJpYWJsZXM6CiAgICAgICAgICAtIGlkCiAgICAgICAgdHJhbnNmb3JtOgogICAgICAgICAgLSBsb3dlcmNhc2UKICAgICAgICAgIC0gdXJsZGVjb2RlCiAgICAgICAgbWF0Y2g6CiAgICAgICAgICB0eXBlOiByZWdleAogICAgICAgICAgdmFsdWU6ICdbXmEtejAtOV0nCgpsYWJlbHM6CiAgdHlwZTogZXhwbG9pdAogIHNlcnZpY2U6IGh0dHAKICBjb25maWRlbmNlOiAzCiAgc3Bvb2ZhYmxlOiAwCiAgYmVoYXZpb3I6ICdodHRwOmV4cGxvaXQnCiAgbGFiZWw6ICdXb3JkUHJlc3MgTVN0b3JlIEFQSSAtIFNRTEknCiAgY2xhc3NpZmljYXRpb246CiAgICAtIGN2ZS5DVkUtMjAyMy0zMTk3CiAgICAtIGF0dGFjay5UMTE5MAogICAgLSBjd2UuQ1dFLTg5Cg==", |
| 2601 | + "description": "Detects unauthenticated SQL injection in WordPress MStore API plugin via id parameter.", |
| 2602 | + "labels": { |
| 2603 | + "behavior": "http:exploit", |
| 2604 | + "classification": [ |
| 2605 | + "cve.CVE-2023-3197", |
| 2606 | + "attack.T1190", |
| 2607 | + "cwe.CWE-89" |
| 2608 | + ], |
| 2609 | + "confidence": 3, |
| 2610 | + "label": "WordPress MStore API - SQLI", |
| 2611 | + "service": "http", |
| 2612 | + "spoofable": 0, |
| 2613 | + "type": "exploit" |
| 2614 | + }, |
| 2615 | + "path": "appsec-rules/crowdsecurity/vpatch-CVE-2023-3197.yaml", |
| 2616 | + "version": "0.1", |
| 2617 | + "versions": { |
| 2618 | + "0.1": { |
| 2619 | + "deprecated": false, |
| 2620 | + "digest": "3aa0ba2809288c222157e493466cd4fde98fdbbe3674442cd5d56c9a9d003ba5" |
| 2621 | + } |
| 2622 | + } |
| 2623 | + }, |
2572 | 2624 | "crowdsecurity/vpatch-CVE-2023-33617": { |
2573 | 2625 | "author": "crowdsecurity", |
2574 | 2626 | "content": "bmFtZTogY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtMzM2MTcKZGVzY3JpcHRpb246ICJBdGxhc3NpYW4gQ29uZmx1ZW5jZSBQcml2ZXNjIChDVkUtMjAyMy0zMzYxNykiCnJ1bGVzOgogIC0gYW5kOgogICAgLSB6b25lczoKICAgICAgLSBNRVRIT0QKICAgICAgdHJhbnNmb3JtOgogICAgICAtIGxvd2VyY2FzZQogICAgICBtYXRjaDoKICAgICAgICB0eXBlOiBlcXVhbHMKICAgICAgICB2YWx1ZTogcG9zdAogICAgLSB6b25lczoKICAgICAgLSBVUkkKICAgICAgdHJhbnNmb3JtOgogICAgICAtIGxvd2VyY2FzZQogICAgICBtYXRjaDoKICAgICAgICB0eXBlOiBlbmRzV2l0aAogICAgICAgIHZhbHVlOiAvYm9hZm9ybS9hZG1pbi9mb3JtbG9naW4KICAgIC0gem9uZXM6CiAgICAgIC0gQk9EWV9BUkdTCiAgICAgIHZhcmlhYmxlczoKICAgICAgIC0gdXNlcm5hbWUKICAgICAgdHJhbnNmb3JtOgogICAgICAtIGxvd2VyY2FzZQogICAgICBtYXRjaDoKICAgICAgICB0eXBlOiBlcXVhbHMKICAgICAgICB2YWx1ZTogImFkbWluIgogICAgLSB6b25lczoKICAgICAgLSBCT0RZX0FSR1MKICAgICAgdmFyaWFibGVzOgogICAgICAgLSBwc2QKICAgICAgdHJhbnNmb3JtOgogICAgICAtIGxvd2VyY2FzZQogICAgICBtYXRjaDoKICAgICAgICB0eXBlOiBlcXVhbHMKICAgICAgICB2YWx1ZTogInBhcmtzIgogIC0gYW5kOgogICAgLSB6b25lczoKICAgICAgLSBNRVRIT0QKICAgICAgbWF0Y2g6CiAgICAgICAgdHlwZTogZXF1YWxzCiAgICAgICAgdmFsdWU6IFBPU1QKICAgIC0gem9uZXM6CiAgICAgIC0gVVJJCiAgICAgIHRyYW5zZm9ybToKICAgICAgLSBsb3dlcmNhc2UKICAgICAgbWF0Y2g6CiAgICAgICAgdHlwZTogZW5kc1dpdGgKICAgICAgICB2YWx1ZTogL2JvYWZvcm0vYWRtaW4vZm9ybXBpbmcKICAgIC0gem9uZXM6CiAgICAgIC0gQk9EWV9BUkdTCiAgICAgIHZhcmlhYmxlczoKICAgICAgLSB0YXJnZXRfYWRkcgogICAgICB0cmFuc2Zvcm06CiAgICAgIC0gbG93ZXJjYXNlCiAgICAgIG1hdGNoOgogICAgICAgIHR5cGU6IHJlZ2V4CiAgICAgICAgdmFsdWU6ICJbXmEtZjAtOTouXSsiCmxhYmVsczoKICB0eXBlOiBleHBsb2l0CiAgc2VydmljZTogaHR0cAogIGNvbmZpZGVuY2U6IDMKICBzcG9vZmFibGU6IDAKICBiZWhhdmlvcjogImh0dHA6ZXhwbG9pdCIKICBsYWJlbDogIkF0bGFzc2lhbiBDb25mbHVlbmNlIC0gUHJpdmlsZWdlIEVzY2FsYXRpb24iCiAgY2xhc3NpZmljYXRpb246CiAgIC0gY3ZlLkNWRS0yMDIzLTMzNjE3CiAgIC0gYXR0YWNrLlQxNTk1CiAgIC0gYXR0YWNrLlQxMTkwCiAgIC0gY3dlLkNXRS03OA==", |
|
8643 | 8695 | "crowdsecurity/vpatch-CVE-2024-1071", |
8644 | 8696 | "crowdsecurity/generic-wordpress-uploads-php", |
8645 | 8697 | "crowdsecurity/vpatch-CVE-2024-6205", |
8646 | | - "crowdsecurity/generic-wordpress-uploads-listing" |
| 8698 | + "crowdsecurity/vpatch-CVE-2022-3254", |
| 8699 | + "crowdsecurity/generic-wordpress-uploads-listing", |
| 8700 | + "crowdsecurity/vpatch-CVE-2023-3197" |
8647 | 8701 | ], |
8648 | 8702 | "author": "crowdsecurity", |
8649 | | - "content": "bmFtZTogY3Jvd2RzZWN1cml0eS9hcHBzZWMtd29yZHByZXNzCmFwcHNlYy1ydWxlczoKICAtIGNyb3dkc2VjdXJpdHkvYmFzZS1jb25maWcKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTA2MDAKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTA5MDAKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTIwMDkKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTIzNDg4CiAgLSBjcm93ZHNlY3VyaXR5L3ZwYXRjaC1DVkUtMjAyMy0yMzQ4OQogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNDYzNAogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNjM2MAogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNjU2NwogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNjYyMwogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjQtMTA2MQogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjQtMTA3MQogIC0gY3Jvd2RzZWN1cml0eS9nZW5lcmljLXdvcmRwcmVzcy11cGxvYWRzLXBocAogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjQtNjIwNQogIC0gY3Jvd2RzZWN1cml0eS9nZW5lcmljLXdvcmRwcmVzcy11cGxvYWRzLWxpc3RpbmcKYXBwc2VjLWNvbmZpZ3M6CiAgLSBjcm93ZHNlY3VyaXR5L3ZpcnR1YWwtcGF0Y2hpbmcKcGFyc2VyczoKICAtIGNyb3dkc2VjdXJpdHkvYXBwc2VjLWxvZ3MKc2NlbmFyaW9zOgogIC0gY3Jvd2RzZWN1cml0eS9hcHBzZWMtdnBhdGNoCiAgLSBjcm93ZHNlY3VyaXR5L2FwcHNlYy1uYXRpdmUKY29udGV4dHM6CiAgLSBjcm93ZHNlY3VyaXR5L2FwcHNlY19iYXNlCmRlc2NyaXB0aW9uOiAiQSB2aXJ0dWFsIHBhdGNoaW5nIGNvbGxlY3Rpb24sIHN1aXRhYmxlIGZvciBXb3JkUHJlc3Mgd2Vic2l0ZXMiCmxhYmVsczoKICBsYWJlbDogIldvcmRQcmVzcyAtIFdBRiBSdWxlcyIKYXV0aG9yOiBjcm93ZHNlY3VyaXR5CnRhZ3M6CiAgLSB3YWYK", |
| 8703 | + "content": "bmFtZTogY3Jvd2RzZWN1cml0eS9hcHBzZWMtd29yZHByZXNzCmFwcHNlYy1ydWxlczoKICAtIGNyb3dkc2VjdXJpdHkvYmFzZS1jb25maWcKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTA2MDAKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTA5MDAKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTIwMDkKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTIzNDg4CiAgLSBjcm93ZHNlY3VyaXR5L3ZwYXRjaC1DVkUtMjAyMy0yMzQ4OQogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNDYzNAogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNjM2MAogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNjU2NwogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjMtNjYyMwogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjQtMTA2MQogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjQtMTA3MQogIC0gY3Jvd2RzZWN1cml0eS9nZW5lcmljLXdvcmRwcmVzcy11cGxvYWRzLXBocAogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjQtNjIwNQogIC0gY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjItMzI1NAogIC0gY3Jvd2RzZWN1cml0eS9nZW5lcmljLXdvcmRwcmVzcy11cGxvYWRzLWxpc3RpbmcKICAtIGNyb3dkc2VjdXJpdHkvdnBhdGNoLUNWRS0yMDIzLTMxOTcKYXBwc2VjLWNvbmZpZ3M6CiAgLSBjcm93ZHNlY3VyaXR5L3ZpcnR1YWwtcGF0Y2hpbmcKcGFyc2VyczoKICAtIGNyb3dkc2VjdXJpdHkvYXBwc2VjLWxvZ3MKc2NlbmFyaW9zOgogIC0gY3Jvd2RzZWN1cml0eS9hcHBzZWMtdnBhdGNoCiAgLSBjcm93ZHNlY3VyaXR5L2FwcHNlYy1uYXRpdmUKY29udGV4dHM6CiAgLSBjcm93ZHNlY3VyaXR5L2FwcHNlY19iYXNlCmRlc2NyaXB0aW9uOiAiQSB2aXJ0dWFsIHBhdGNoaW5nIGNvbGxlY3Rpb24sIHN1aXRhYmxlIGZvciBXb3JkUHJlc3Mgd2Vic2l0ZXMiCmxhYmVsczoKICBsYWJlbDogIldvcmRQcmVzcyAtIFdBRiBSdWxlcyIKYXV0aG9yOiBjcm93ZHNlY3VyaXR5CnRhZ3M6CiAgLSB3YWYK", |
8650 | 8704 | "contexts": [ |
8651 | 8705 | "crowdsecurity/appsec_base" |
8652 | 8706 | ], |
|
8663 | 8717 | "crowdsecurity/appsec-vpatch", |
8664 | 8718 | "crowdsecurity/appsec-native" |
8665 | 8719 | ], |
8666 | | - "version": "0.7", |
| 8720 | + "version": "0.9", |
8667 | 8721 | "versions": { |
8668 | 8722 | "0.1": { |
8669 | 8723 | "deprecated": false, |
|
8692 | 8746 | "0.7": { |
8693 | 8747 | "deprecated": false, |
8694 | 8748 | "digest": "37d84182a2fc459aec85da16d52c245971d3901c580d7d74175fe4d135aaae75" |
| 8749 | + }, |
| 8750 | + "0.8": { |
| 8751 | + "deprecated": false, |
| 8752 | + "digest": "8275e964719ea8bc0530c9fd06fad7e6ed4975a80cc1d94c4e82c2ca67c0cb1c" |
| 8753 | + }, |
| 8754 | + "0.9": { |
| 8755 | + "deprecated": false, |
| 8756 | + "digest": "81650393ee520918ae7299d7c0f3809d4707714421e62445ab5357e3fc7207d1" |
8695 | 8757 | } |
8696 | 8758 | } |
8697 | 8759 | }, |
|
0 commit comments