Skip to content

Add vpatch-CVE-2024-8181 rule and test#41

Merged
he2ss merged 6 commits into
masterfrom
1781255703-vpatch-CVE-2024-8181
Jun 12, 2026
Merged

Add vpatch-CVE-2024-8181 rule and test#41
he2ss merged 6 commits into
masterfrom
1781255703-vpatch-CVE-2024-8181

Conversation

@crowdsec-automation

Copy link
Copy Markdown

This rule detects attempts to exploit the authentication bypass vulnerability in Flowise <= 1.8.2 (CVE-2024-8181). The attack leverages a crafted URI that includes both /api/v1/apikey and /api/v1/ping, which allows unauthenticated access to sensitive API endpoints. The rule matches requests where the URI contains both /api/v1/apikey and /api/v1/ping (case-insensitive and URL-decoded), which is the unique pattern used in the exploit. No argument or header matching is needed, as the bypass is achieved solely via the crafted URI. The labels section includes the correct CVE, ATT&CK, and CWE references. All value: fields are lowercase, and the transform section includes lowercase and urldecode to ensure normalization and prevent bypasses due to case or encoding. The test config and nuclei test template are adapted to expect a 403 response, as required.

@github-actions

Copy link
Copy Markdown

Hello @crowdsec-automation and thank you for your contribution!

❗ It seems that the following scenarios are not part of the 'crowdsecurity/appsec-virtual-patching' collection:

🔴 crowdsecurity/vpatch-CVE-2024-8181 🔴

@github-actions

Copy link
Copy Markdown

Hello @crowdsec-automation,

Scenarios/AppSec Rule are compliant with the taxonomy, thank you for your contribution!

Updated match value to include both '/api/v1/apikey' and '/api/v1/ping'.
@github-actions

Copy link
Copy Markdown

Hello @he2ss,

✅ The new VPATCH Rule is compliant, thank you for your contribution!

@github-actions

Copy link
Copy Markdown

Hello @he2ss,

Scenarios/AppSec Rule are compliant with the taxonomy, thank you for your contribution!

@github-actions

Copy link
Copy Markdown

Hello @he2ss,

✅ The new VPATCH Rule is compliant, thank you for your contribution!

@github-actions

Copy link
Copy Markdown

Hello @he2ss,

Scenarios/AppSec Rule are compliant with the taxonomy, thank you for your contribution!

@he2ss he2ss merged commit aa00d02 into master Jun 12, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants