secubox-deb/packages/secubox-cve-triage/nuclei-subset/CVE-2024-21887.yaml
CyberMind-FR dc190aa049 fix(cve-triage): is_kev reads info.tags (real nuclei format) + CLI main() tests
is_kev() read tags at the template's top level while extract() already read
classification/metadata from under info: — real upstream nuclei-templates
nest tags under info: too, so a real curation run silently produced zero
candidates. Read info.tags first with a top-level fallback for legacy
fixtures, and realign the two vendored KEV templates to the real nested
format. Also add direct coverage of cli.main() (dry-run no-op, --apply
writing only product_absent_probes, and the incomplete-inventory fail-safe
returning 3 without touching the rules file).

Co-Authored-By: Gerald KERMA <devel@cybermind.fr>
2026-07-18 08:06:20 +02:00

16 lines
375 B
YAML

id: CVE-2024-21887
info:
name: Ivanti Connect Secure - Command Injection
severity: critical
classification:
cve-id: CVE-2024-21887
cpe: cpe:2.3:a:ivanti:connect_secure:*:*:*:*:*:*:*:*
metadata:
vendor: ivanti
product: connect_secure
tags: cve,cve2024,ivanti,rce,kev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/api/v1/totp/user-backup"