HTTP: Crush FTP Server Side Template Injection

This signature detects attempts to exploit a known vulnerability against Crush FTP. A successful attack can lead to sensitive information disclosure.

Extended Description

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

Affected Products

Crushftp crushftp

References

CVE: CVE-2024-4040

Short Name
HTTP:CTS:CRUSH-FTP-SSTI
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2024-4040 Crush FTP Injection Server Side Template
Release Date
06/20/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3715
False Positive
Unknown
Vendors

Crushftp

Found a potential security threat?