Add CVE triage and disposition artifacts for scan hits
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
{
|
||||
"host": "nextcloud.lan.ddnsgeek.com",
|
||||
"generated_at": "2026-04-07T03:49:38.723646+00:00",
|
||||
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
||||
"findings": [
|
||||
{
|
||||
"host": "nextcloud.lan.ddnsgeek.com",
|
||||
"cve": "CVE-2003-1418",
|
||||
"affected_host": "nextcloud.lan.ddnsgeek.com",
|
||||
"endpoint": "unknown",
|
||||
"product_version_evidence": [
|
||||
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
||||
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
||||
"http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
||||
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
||||
"ssl/http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API)",
|
||||
"tcpwrapped syn-ack ttl 56"
|
||||
],
|
||||
"exploit_precondition": "Target must expose Apache mod_include with vulnerable SSI execution behavior.",
|
||||
"reproducibility": "not-reproduced",
|
||||
"disposition": "needs-manual-test",
|
||||
"disposition_rationale": "Signature-based identification only; exploitability depends on module/configuration and requires targeted validation.",
|
||||
"required_reproduction_step_before_ticket": "Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient.",
|
||||
"evidence_sources": [
|
||||
{
|
||||
"file": "results/nextcloud.lan.ddnsgeek.com/scans/_patterns.log",
|
||||
"match_count": 1
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
# CVE triage sheet - nextcloud.lan.ddnsgeek.com
|
||||
|
||||
Generated (UTC): 2026-04-07T03:49:38.723646+00:00
|
||||
|
||||
| CVE | Affected host | Endpoint | Product/version evidence | Exploit precondition | Reproducibility | Disposition |
|
||||
|---|---|---|---|---|---|---|
|
||||
| CVE-2003-1418 | nextcloud.lan.ddnsgeek.com | `unknown` | http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API); http syn-ack ttl 55 Golang net/http server (Go-IPFS json-rpc or InfluxDB API) | Target must expose Apache mod_include with vulnerable SSI execution behavior. | not-reproduced | **needs-manual-test** |
|
||||
| | | | | | | Required reproduction gate: Before creating a ticket, reproduce vulnerable behavior directly (e.g., crafted request causing data exposure, traversal read, or exploitable crash) and attach request/response proof. Banner or script signature matches alone are insufficient. |
|
||||
Reference in New Issue
Block a user