HTTP: CachetHQ Cachet CreateIncidentCommandHandler.php Template Injection

This signature detects attempts to exploit a known vulnerability against CachetHQ Cachet. A successful attack can lead to arbitrary code execution.

Extended Description

Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of the 2.4 branch contains a patch for this issue.

Affected Products

All-three cachet

Short Name
HTTP:CTS:CACHET-HQ-TEMP-INJ
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2023-43661 Cachet CachetHQ CreateIncidentCommandHandler.php Injection Template
Release Date
11/21/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3653
False Positive
Rarely
Vendors

All-three

Found a potential security threat?