shubs

@shubs.io

Co-founder, security researcher. Building an attack surface management platform, @assetnote.io

Rapid7 analysis of Apache #Struts 2 CVE-2024-53677 here via research lead Ryan Emmons — highlights: * No, this isn't really being successfully exploited in the wild * Payloads need to be customized to the target * The 'fixed' version *does not* remediate the vuln attackerkb.com/assessments/...

remmons-r7's assessment of CVE-2024-53677 | AttackerKB

CVE-2024-53677 is a flawed upload logic vulnerability in Apache Struts 2. The vulnerability permits an attacker to override internal file upload variables in a…

attackerkb.com

Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE. Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...

Bild