Skip to content

Conversation

@halencarjunior
Copy link
Contributor

@halencarjunior halencarjunior commented Feb 13, 2025

Template / PR Information

This template detects an authentication bypass vulnerability in PAN-OS caused by path confusion between Nginx and Apache.
The vulnerability arises due to improper handling of double URL-encoded paths, allowing attackers to bypass authentication.

https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os
https://security.paloaltonetworks.com/CVE-2025-0108

Template Validation

I've validated this template locally?

  • YES
  • NO

Additional References:

@halencarjunior halencarjunior changed the title Adding CVE-2025-0108 for PAN-OS Added CVE-2025-0108 Feb 13, 2025
@GeorginaReeder
Copy link

Thanks for your contribution @halencarjunior , we appreciate it! :)

@DhiyaneshGeek DhiyaneshGeek self-assigned this Feb 15, 2025
@DhiyaneshGeek DhiyaneshGeek added Done Ready to merge good first issue Good for newcomers labels Feb 15, 2025
@pussycat0x
Copy link
Contributor

Hello @halencarjunior , thank you so much for sharing this template with the community and contributing to this project 🍻
You can grab some cool PD stickers over here http://nux.gg/stickers 😄

@DhiyaneshGeek DhiyaneshGeek merged commit e39d18b into projectdiscovery:main Feb 20, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Done Ready to merge good first issue Good for newcomers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants