Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
Make sure to apply the patch as soon as possible
- Popular open source vulnerability scanner Nuclei was found to be vulnerable itself
- A bug allowed crooks to smuggle malicious code past the scanner
- The vulnerability was fixed in September 2024, but many users still haven't updated
A vulnerability scanning tool was found to have been vulnerable itself, allowing crooks to smuggle malicious code past the gatekeeper.
Cybersecurity researcher from Wiz, Guy Goldenberg, found a bug in ProjectDiscovery’s Nuclei in August 2024, after investigating the open source vulnerability scanner, which is designed to automate the detection of security issues across various protocols, systems, and applications using customizable YAML-based templates.
The bug is tracked as CVE-2024-43405, and was given a severity score of 7.8 (high). In versions 3.0.0 - 3.3.2, a vulnerability in Nuclei's template signature verification system allowed malicious actors to bypass signature checks and possibly run malicious code via custom code template, it was said.
Upgrades and workarounds
A fix was released in early September 2024, making version 3.3.2 the first clean one. Users are urged to apply the fix immediately, since cybercriminals are expected to now start scanning for vulnerable endpoints. Those that cannot apply the patch in a timely manner should stop using custom templates, and instead only use trusted, verified ones.
“Those who are unable to upgrade Nuclei should disable running custom code templates as a workaround,” it was explained on the NVD webpage.
Wiz also stated that Nuclei should be used in a virtual machine, or isolated environment.
While open source software is generally considered safe (if nothing else, then due to countless eyes looking at the code all the time), its popularity and ease of access also make it a popular target for criminals interested in software supply chain attacks. While the exact number of Nuclei users is impossible to determine, we can say it is a popular solution, since it has 21,000 stars on GitHub, paired with roughly 2,600 forks.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Additionally, the Nuclei project boasts more than 700 contributors and has facilitated over 50 million monthly scans, indicating widespread adoption within the cybersecurity community.
Via BleepingComputer
You might also like
- More threats against open source software could be coming soon, experts warn
- Here's a list of the best antivirus tools on offer
- These are the best endpoint protection tools right now
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.