Skip to content

Commit 13de54f

Browse files
Add vpatch-CVE-2024-6235 rule and test (#1590)
* Add vpatch-CVE-2024-6235 rule * Add vpatch-CVE-2024-6235 test config --------- Co-authored-by: Thibault "bui" Koechlin <thibault@crowdsec.net>
1 parent 292a8ef commit 13de54f

File tree

4 files changed

+64
-0
lines changed

4 files changed

+64
-0
lines changed
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
## autogenerated on 2025-11-28 14:43:34
2+
id: CVE-2024-6235
3+
info:
4+
name: CVE-2024-6235
5+
author: crowdsec
6+
severity: info
7+
description: CVE-2024-6235 testing
8+
tags: appsec-testing
9+
http:
10+
- raw:
11+
- |
12+
GET /internal/v2/config/mps_secret/ADM_SESSIONID HTTP/1.1
13+
Host: {{Hostname}}
14+
Referer: {{RootURL}}/admin_ui/mas/ent/html/main.html
15+
Content-Type: application/json
16+
If-Modified-Since: Thu, 01 Jan 1970 05:30:00 GMT
17+
NITRO_WEB_APPLICATION: true
18+
Tenant-Name: Owner
19+
User-Name: nsroot
20+
Mps-Internal-Request: true
21+
cookie-reuse: true
22+
matchers:
23+
- type: status
24+
status:
25+
- 403
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
## autogenerated on 2025-11-28 14:43:34
2+
appsec-rules:
3+
- ./appsec-rules/crowdsecurity/base-config.yaml
4+
- ./appsec-rules/crowdsecurity/vpatch-CVE-2024-6235.yaml
5+
nuclei_template: CVE-2024-6235.yaml
Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
## autogenerated on 2025-11-28 14:43:34
2+
name: crowdsecurity/vpatch-CVE-2024-6235
3+
description: 'Detects unauthorized access to sensitive NetScaler Console configuration endpoint disclosing ADM_SESSIONID.'
4+
rules:
5+
- and:
6+
- zones:
7+
- URI
8+
transform:
9+
- lowercase
10+
match:
11+
type: contains
12+
value: /internal/v2/config/mps_secret/adm_sessionid
13+
- zones:
14+
- HEADERS
15+
variables:
16+
- user-name
17+
transform:
18+
- lowercase
19+
match:
20+
type: equals
21+
value: nsroot
22+
23+
labels:
24+
type: exploit
25+
service: http
26+
confidence: 3
27+
spoofable: 0
28+
behavior: 'http:exploit'
29+
label: 'NetScaler Console - Sensitive Information Disclosure'
30+
classification:
31+
- cve.CVE-2024-6235
32+
- attack.T1592
33+
- cwe.CWE-200

collections/crowdsecurity/appsec-virtual-patching.yaml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -139,6 +139,7 @@ appsec-rules:
139139
- crowdsecurity/vpatch-CVE-2025-27222
140140
- crowdsecurity/vpatch-CVE-2025-64446
141141
- crowdsecurity/vpatch-CVE-2020-10987
142+
- crowdsecurity/vpatch-CVE-2024-6235
142143
author: crowdsecurity
143144
contexts:
144145
- crowdsecurity/appsec_base

0 commit comments

Comments
 (0)