Remediation Recommendations (Summary)
2024-09-12
Mainly for convenient copy/paste when writing reports.
2738 words
|
14 minutes
Template Injection in a Report System
2024-07-23
This vulnerability was described publicly as an SQL injection, but in reality it is a template injection.
290 words
|
1 minute
(CVE-2023-22527) Atlassian Confluence - Remote Code Execution
2024-01-23
Atlassian Confluence contains a template injection vulnerability. An attacker can craft a malicious request to trigger template injection and achieve remote command execution.
318 words
|
2 minutes
CVE-2023-51467 Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
2023-12-30
The authentication bypass in the previously disclosed OFBiz issue was not fully fixed, which led to this vulnerability. By reaching the Groovy execution path from an external entry point and bypassing the blacklist, an attacker can achieve RCE.
224 words
|
1 minute
CVE-2022-41678 Apache ActiveMQ Jolokia RCE
2023-12-01
There have been several ActiveMQ vulnerabilities recently. I saw others already analyzed them, so I didn’t dig too deeply at the time. Then an older issue from last year got re-surfaced, so I wrote these notes in one go (also because I hadn’t systematically studied ActiveMQ, so this was a good excuse).
663 words
|
3 minutes
I DOC VIEW Frontend RCE
2023-11-24
I DOC VIEW is an online document viewer. Due to improper handling in the /html/2word endpoint, an attacker can read arbitrary files remotely. By abusing this endpoint to make the server download and parse a malicious JSP, this can be escalated to RCE.
503 words
|
3 minutes
A Brief Look at JWT Security
2023-11-22
JWT was introduced to avoid frequent database lookups for maintaining HTTP session state. Unlike Redis, JWT stores most (or all) session information inside the token itself. By parsing the JWT, the application can retrieve session state directly — but this also introduces security risks.
1013 words
|
5 minutes