diff --git a/.appsec-tests/vpatch-CVE-2024-32870/CVE-2024-32870.yaml b/.appsec-tests/vpatch-CVE-2024-32870/CVE-2024-32870.yaml new file mode 100644 index 00000000000..36bcbae6b15 --- /dev/null +++ b/.appsec-tests/vpatch-CVE-2024-32870/CVE-2024-32870.yaml @@ -0,0 +1,17 @@ +## autogenerated on 2025-05-09 09:55:11 +id: CVE-2024-32870 +info: + name: CVE-2024-32870 + author: crowdsec + severity: info + description: CVE-2024-32870 testing + tags: appsec-testing +http: + - method: GET + path: + - "{{BaseURL}}/pages/exec.php?exec_module=itop-hub-connector&exec_page=launch.php&target=inform_after_setup" + cookie-reuse: true + matchers: + - type: status + status: + - 403 diff --git a/.appsec-tests/vpatch-CVE-2024-32870/config.yaml b/.appsec-tests/vpatch-CVE-2024-32870/config.yaml new file mode 100644 index 00000000000..a0e409d45cd --- /dev/null +++ b/.appsec-tests/vpatch-CVE-2024-32870/config.yaml @@ -0,0 +1,5 @@ +## autogenerated on 2025-05-09 09:55:11 +appsec-rules: + - ./appsec-rules/crowdsecurity/base-config.yaml + - ./appsec-rules/crowdsecurity/vpatch-CVE-2024-32870.yaml +nuclei_template: CVE-2024-32870.yaml diff --git a/appsec-rules/crowdsecurity/vpatch-CVE-2024-32870.yaml b/appsec-rules/crowdsecurity/vpatch-CVE-2024-32870.yaml new file mode 100644 index 00000000000..f2ad77c39cd --- /dev/null +++ b/appsec-rules/crowdsecurity/vpatch-CVE-2024-32870.yaml @@ -0,0 +1,55 @@ +## autogenerated on 2025-05-09 09:55:11 +name: crowdsecurity/vpatch-CVE-2024-32870 +description: 'Detects unauthenticated access to iTop Hub Connector information disclosure endpoint.' +rules: + - and: + - zones: + - URI + transform: + - lowercase + - urldecode + match: + type: contains + value: /pages/exec.php + - zones: + - ARGS + variables: + - exec_module + transform: + - lowercase + - urldecode + match: + type: equals + value: itop-hub-connector + - zones: + - ARGS + variables: + - exec_page + transform: + - lowercase + - urldecode + match: + type: equals + value: launch.php + - zones: + - ARGS + variables: + - target + transform: + - lowercase + - urldecode + match: + type: equals + value: inform_after_setup + +labels: + type: exploit + service: http + confidence: 3 + spoofable: 0 + behavior: 'http:exploit' + label: 'iTop Hub Connector - Information Disclosure' + classification: + - cve.CVE-2024-32870 + - attack.T1592 + - cwe.CWE-200 diff --git a/collections/crowdsecurity/appsec-virtual-patching.yaml b/collections/crowdsecurity/appsec-virtual-patching.yaml index be69426f031..dbc13b746d9 100644 --- a/collections/crowdsecurity/appsec-virtual-patching.yaml +++ b/collections/crowdsecurity/appsec-virtual-patching.yaml @@ -90,6 +90,7 @@ appsec-rules: - crowdsecurity/vpatch-CVE-2024-27292 - crowdsecurity/vpatch-CVE-2025-24893 - crowdsecurity/vpatch-CVE-2021-43798 +- crowdsecurity/vpatch-CVE-2024-32870 author: crowdsecurity contexts: - crowdsecurity/appsec_base