google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
872 stars 176 forks source link

PRP: F5 BIG-IP - Unauthenticated RCE via AJP Smuggling #365

Open secureness opened 9 months ago

secureness commented 9 months ago

Hi, I want to implement a tsunami security scanner plugin for CVE-2023-46747. due to the critical public usage of F5 BIG-IP on the internet, I recommend that I start working on this plugin ASAP.

tooryx commented 8 months ago

Hi @secureness,

Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!