Skip to content

[FALSE-POSITIVE] CVE-2023-45648 as weak Regex #15566

@tarunkant

Description

@tarunkant

Template IDs or paths

- CVE-2023-45648

[CVE-2023-45648] [http] [medium] https://XXXXXXX.REDACTED.com/3ATkDf9MOIGLVCBPZYVWRU9TLhI ["9.0.111"]

But 9.0.111 is not a vulnerable version based on CVE details or template description but a weak regex is detecting this as a vulnerable domain.

Please look into it.

Environment

- OS: 
- Nuclei: 
- Go:

Steps To Reproduce

nuclei -target "https://XXXXX.REDACTED.com/" -t ./http/cves/2023/CVE-2023-45648.yaml

Relevant dumped responses

Anything else?

No response

Metadata

Metadata

Assignees

Labels

false-positiveNuclei template reporting invalid/unexpected result

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions