Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw

coding
(Image credit: Pixabay)

  • Popular open source vulnerability scanner Nuclei was found to be vulnerable itself
  • A bug allowed crooks to smuggle malicious code past the scanner
  • The vulnerability was fixed in September 2024, but many users still haven't updated

A vulnerability scanning tool was found to have been vulnerable itself, allowing crooks to smuggle malicious code past the gatekeeper.

Cybersecurity researcher from Wiz, Guy Goldenberg, found a bug in ProjectDiscovery’s Nuclei in August 2024, after investigating the open source vulnerability scanner, which is designed to automate the detection of security issues across various protocols, systems, and applications using customizable YAML-based templates.

The bug is tracked as CVE-2024-43405, and was given a severity score of 7.8 (high). In versions 3.0.0 - 3.3.2, a vulnerability in Nuclei's template signature verification system allowed malicious actors to bypass signature checks and possibly run malicious code via custom code template, it was said.

Upgrades and workarounds

A fix was released in early September 2024, making version 3.3.2 the first clean one. Users are urged to apply the fix immediately, since cybercriminals are expected to now start scanning for vulnerable endpoints. Those that cannot apply the patch in a timely manner should stop using custom templates, and instead only use trusted, verified ones.

“Those who are unable to upgrade Nuclei should disable running custom code templates as a workaround,” it was explained on the NVD webpage.

Wiz also stated that Nuclei should be used in a virtual machine, or isolated environment.

While open source software is generally considered safe (if nothing else, then due to countless eyes looking at the code all the time), its popularity and ease of access also make it a popular target for criminals interested in software supply chain attacks. While the exact number of Nuclei users is impossible to determine, we can say it is a popular solution, since it has 21,000 stars on GitHub, paired with roughly 2,600 forks.

Additionally, the Nuclei project boasts more than 700 contributors and has facilitated over 50 million monthly scans, indicating widespread adoption within the cybersecurity community.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cyber-security
Top file-sharing tools are being hit by security attacks once again
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
An abstract image of digital security.
Tenable warns users to update now following possible plugin security issue
Digital image of a lock.
Fortinet flags some worrying security bugs coming back from the dead
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Huge cybercrime attack sees 390,000 WordPress websites hit, details stolen
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price