File tree Expand file tree Collapse file tree 1 file changed +26
-0
lines changed
Expand file tree Collapse file tree 1 file changed +26
-0
lines changed Original file line number Diff line number Diff line change 47964796 }
47974797 }
47984798 },
4799+ "crowdsecurity/vpatch-CVE-2025-40552": {
4800+ "author": "crowdsecurity",
4801+ "content": "bmFtZTogY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjUtNDA1NTIKZGVzY3JpcHRpb246ICdEZXRlY3RzIGF1dGhlbnRpY2F0aW9uIGJ5cGFzcyBpbiBTb2xhcldpbmRzIFdlYiBIZWxwIERlc2sgdmlhIFdlYk9iamVjdHMgd29wYWdlIHBhcmFtZXRlciBhY2Nlc3MgdG8gc2Vuc2l0aXZlIHBhZ2VzJwpydWxlczoKICAtIGFuZDoKICAgICAgLSB6b25lczoKICAgICAgICAgIC0gVVJJCiAgICAgICAgdHJhbnNmb3JtOgogICAgICAgICAgLSBsb3dlcmNhc2UKICAgICAgICAgIC0gdXJsZGVjb2RlCiAgICAgICAgbWF0Y2g6CiAgICAgICAgICB0eXBlOiBjb250YWlucwogICAgICAgICAgdmFsdWU6ICcvaGVscGRlc2svd2Vib2JqZWN0cy9oZWxwZGVzay53b2Evd28vJwogICAgICAtIHpvbmVzOgogICAgICAgICAgLSBCT0RZX0FSR1MKICAgICAgICB2YXJpYWJsZXM6CiAgICAgICAgICAtIHdvcGFnZQogICAgICAgIHRyYW5zZm9ybToKICAgICAgICAgIC0gbG93ZXJjYXNlCiAgICAgICAgICAtIHVybGRlY29kZQogICAgICAgIG1hdGNoOgogICAgICAgICAgdHlwZTogcmVnZXgKICAgICAgICAgIHZhbHVlOiAnLisnCgpsYWJlbHM6CiAgdHlwZTogZXhwbG9pdAogIHNlcnZpY2U6IGh0dHAKICBjb25maWRlbmNlOiAzCiAgc3Bvb2ZhYmxlOiAwCiAgYmVoYXZpb3I6ICdodHRwOmV4cGxvaXQnCiAgbGFiZWw6ICdTb2xhcldpbmRzIFdlYiBIZWxwIERlc2sgLSBBdXRoZW50aWNhdGlvbiBCeXBhc3MnCiAgY2xhc3NpZmljYXRpb246CiAgICAtIGN2ZS5DVkUtMjAyNS00MDU1MgogICAgLSBhdHRhY2suVDExOTAKICAgIC0gY3dlLkNXRS0yODc=",
4802+ "description": "Detects authentication bypass in SolarWinds Web Help Desk via WebObjects wopage parameter access to sensitive pages",
4803+ "labels": {
4804+ "behavior": "http:exploit",
4805+ "classification": [
4806+ "cve.CVE-2025-40552",
4807+ "attack.T1190",
4808+ "cwe.CWE-287"
4809+ ],
4810+ "confidence": 3,
4811+ "label": "SolarWinds Web Help Desk - Authentication Bypass",
4812+ "service": "http",
4813+ "spoofable": 0,
4814+ "type": "exploit"
4815+ },
4816+ "path": "appsec-rules/crowdsecurity/vpatch-CVE-2025-40552.yaml",
4817+ "version": "0.1",
4818+ "versions": {
4819+ "0.1": {
4820+ "deprecated": false,
4821+ "digest": "9865b6027bb45ca1a41207488564774105f8db4ed51112b6eb8f447f5d8daadc"
4822+ }
4823+ }
4824+ },
47994825 "crowdsecurity/vpatch-CVE-2025-4689": {
48004826 "author": "crowdsecurity",
48014827 "content": "bmFtZTogY3Jvd2RzZWN1cml0eS92cGF0Y2gtQ1ZFLTIwMjUtNDY4OQpkZXNjcmlwdGlvbjogJ0RldGVjdHMgV29yZFByZXNzIEFkcyBQcm8gUGx1Z2luIHVuYXV0aGVudGljYXRlZCBTUUxpICsgTEZJIGNoYWluIHZpYSB3cC1hamF4IGVuZHBvaW50IHRhcmdldGluZyBhX2lkIHBhcmFtZXRlciAoQ1ZFLTIwMjUtNDY4OSknCnJ1bGVzOgogIC0gYW5kOgogICAgICAtIHpvbmVzOgogICAgICAgICAgLSBVUkkKICAgICAgICB0cmFuc2Zvcm06CiAgICAgICAgICAtIGxvd2VyY2FzZQogICAgICAgICAgLSB1cmxkZWNvZGUKICAgICAgICBtYXRjaDoKICAgICAgICAgIHR5cGU6IGNvbnRhaW5zCiAgICAgICAgICB2YWx1ZTogJy93cC1hZG1pbi9hZG1pbi1hamF4LnBocCcKICAgICAgLSB6b25lczoKICAgICAgICAgIC0gQVJHUwogICAgICAgIHZhcmlhYmxlczoKICAgICAgICAgIC0gYWN0aW9uCiAgICAgICAgdHJhbnNmb3JtOgogICAgICAgICAgLSBsb3dlcmNhc2UKICAgICAgICAgIC0gdXJsZGVjb2RlCiAgICAgICAgbWF0Y2g6CiAgICAgICAgICB0eXBlOiBjb250YWlucwogICAgICAgICAgdmFsdWU6ICdic2FfcHJvJwogICAgICAtIHpvbmVzOgogICAgICAgICAgLSBBUkdTCiAgICAgICAgdmFyaWFibGVzOgogICAgICAgICAgLSBhX2lkCiAgICAgICAgdHJhbnNmb3JtOgogICAgICAgICAgLSBsb3dlcmNhc2UKICAgICAgICAgIC0gdXJsZGVjb2RlCiAgICAgICAgbWF0Y2g6CiAgICAgICAgICB0eXBlOiByZWdleAogICAgICAgICAgdmFsdWU6ICJbXjAtOV0iCmxhYmVsczoKICB0eXBlOiBleHBsb2l0CiAgc2VydmljZTogaHR0cAogIGNvbmZpZGVuY2U6IDMKICBzcG9vZmFibGU6IDAKICBiZWhhdmlvcjogJ2h0dHA6ZXhwbG9pdCcKICBsYWJlbDogJ1dvcmRQcmVzcyBBZHMgUHJvIFBsdWdpbiAtIFNRTEknCiAgY2xhc3NpZmljYXRpb246CiAgICAtIGN2ZS5DVkUtMjAyNS00Njg5CiAgICAtIGF0dGFjay5UMTE5MAogICAgLSBjd2UuQ1dFLTg5",
You can’t perform that action at this time.
0 commit comments