Nuclei Security Update Advisory (CVE-2024-43405)
Overview
We have released a security update to address a vulnerability in Nuclei. affected product users are advised to update to the latest version.
Affected Products
CVE-2024-43405
Nuclei Versions: 3.0.0 (inclusive) through 3.3.2 (excluded)
Resolved Vulnerabilities
Command Injection vulnerability in Nuclei’s template signature validation system (CVE-2024-43405)
Vulnerability Patches
vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-43405
Nuclei Version: 3.3.2
references
[1] Nuclei Template Signature Verification Bypass
https://github.com/projectdiscovery/nuclei/security/advisories/GHSA-7h5p-mmpp-hgmm