Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unauthorized-zookeeper #11076

Open
1 task done
h1thub opened this issue Oct 23, 2024 · 1 comment
Open
1 task done

Unauthorized-zookeeper #11076

h1thub opened this issue Oct 23, 2024 · 1 comment
Assignees
Labels
Status: In Progress This issue is being worked on, and has someone assigned. template-requests Request for new Nuclei templates to be created

Comments

@h1thub
Copy link

h1thub commented Oct 23, 2024

Is there an existing template for this?

  • I have searched the existing templates.

Template requests

The existing exposed-zookeeper.yaml PoC only uses Zookeeper's four-letter commands to verify the existence of the vulnerability. However, this approach has a significant limitation: if the target Zookeeper instance employs a whitelist to restrict certain four-letter commands, it may lead to a situation where the unauthorized access vulnerability actually exists, but is not detected. Therefore, we are modifying the new PoC as follows, with the relevant details provided below.

https://github.com/h1thub/Unauthorized-zookeeper

Anything else?

No response

@h1thub h1thub added the template-requests Request for new Nuclei templates to be created label Oct 23, 2024
@ritikchaddha
Copy link
Contributor

Hello @h1thub, thank you for your help in updating the template. We will review it and update you shortly.

@ritikchaddha ritikchaddha added the Status: In Progress This issue is being worked on, and has someone assigned. label Nov 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Status: In Progress This issue is being worked on, and has someone assigned. template-requests Request for new Nuclei templates to be created
Projects
None yet
Development

No branches or pull requests

2 participants