2020-12-31 06:09:58 +09:00
[
2021-04-05 12:11:01 +09:00
{
"id" : 265151514 ,
"name" : "tomcat-cluster-session-sync-exp" ,
"full_name" : "threedr3am\/tomcat-cluster-session-sync-exp" ,
"owner" : {
"login" : "threedr3am" ,
"id" : 19884279 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/19884279?v=4" ,
"html_url" : "https:\/\/github.com\/threedr3am"
} ,
"html_url" : "https:\/\/github.com\/threedr3am\/tomcat-cluster-session-sync-exp" ,
"description" : "tomcat使用了自带session同步功能时, 不安全的配置( 没有使用EncryptInterceptor) 导致存在的反序列化漏洞, 通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484, 9484是session持久化的洞, 这个是session集群同步的洞! " ,
"fork" : false ,
"created_at" : "2020-05-19T05:12:53Z" ,
2023-03-28 09:29:17 +09:00
"updated_at" : "2023-03-27T19:30:23Z" ,
2021-04-05 12:11:01 +09:00
"pushed_at" : "2020-05-19T05:13:19Z" ,
2023-03-28 09:29:17 +09:00
"stargazers_count" : 213 ,
"watchers_count" : 213 ,
2022-11-08 09:17:44 +09:00
"has_discussions" : false ,
2023-05-06 21:28:28 +09:00
"forks_count" : 39 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [ ] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2023-05-06 21:28:28 +09:00
"forks" : 39 ,
2023-03-28 09:29:17 +09:00
"watchers" : 213 ,
2021-04-05 12:11:01 +09:00
"score" : 0
} ,
{
"id" : 265717610 ,
"name" : "CVE-2020-9484" ,
"full_name" : "masahiro331\/CVE-2020-9484" ,
"owner" : {
"login" : "masahiro331" ,
"id" : 20438853 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/20438853?v=4" ,
"html_url" : "https:\/\/github.com\/masahiro331"
} ,
"html_url" : "https:\/\/github.com\/masahiro331\/CVE-2020-9484" ,
"description" : null ,
"fork" : false ,
"created_at" : "2020-05-21T00:41:06Z" ,
2022-12-23 09:25:42 +09:00
"updated_at" : "2022-12-22T18:57:35Z" ,
2021-10-28 12:12:48 +09:00
"pushed_at" : "2021-10-28T02:31:04Z" ,
2022-12-23 09:25:42 +09:00
"stargazers_count" : 126 ,
"watchers_count" : 126 ,
2022-11-08 15:19:29 +09:00
"has_discussions" : false ,
2023-05-07 09:28:57 +09:00
"forks_count" : 31 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [ ] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2023-05-07 09:28:57 +09:00
"forks" : 31 ,
2022-12-23 09:25:42 +09:00
"watchers" : 126 ,
2021-04-05 12:11:01 +09:00
"score" : 0
} ,
2022-03-23 21:15:41 +09:00
{
"id" : 265741960 ,
"name" : "CVE-2020-9484" ,
"full_name" : "seanachao\/CVE-2020-9484" ,
"owner" : {
"login" : "seanachao" ,
"id" : 30539692 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/30539692?v=4" ,
"html_url" : "https:\/\/github.com\/seanachao"
} ,
"html_url" : "https:\/\/github.com\/seanachao\/CVE-2020-9484" ,
"description" : "利用ceye批量检测CVE-2020-9484" ,
"fork" : false ,
"created_at" : "2020-05-21T03:07:24Z" ,
"updated_at" : "2022-03-23T08:03:58Z" ,
"pushed_at" : "2020-05-21T02:30:47Z" ,
"stargazers_count" : 0 ,
"watchers_count" : 0 ,
2022-11-08 09:17:44 +09:00
"has_discussions" : false ,
2022-03-23 21:15:41 +09:00
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2022-03-23 21:15:41 +09:00
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
"watchers" : 0 ,
"score" : 0
} ,
2021-04-05 12:11:01 +09:00
{
"id" : 265870392 ,
"name" : "CVE-2020-9484" ,
"full_name" : "IdealDreamLast\/CVE-2020-9484" ,
"owner" : {
"login" : "IdealDreamLast" ,
"id" : 33090510 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/33090510?v=4" ,
"html_url" : "https:\/\/github.com\/IdealDreamLast"
} ,
"html_url" : "https:\/\/github.com\/IdealDreamLast\/CVE-2020-9484" ,
"description" : "用Kali 2.0复现Apache Tomcat Session反序列化代码执行漏洞" ,
"fork" : false ,
"created_at" : "2020-05-21T14:30:46Z" ,
2023-03-13 03:28:05 +09:00
"updated_at" : "2023-03-12T16:16:36Z" ,
2021-04-05 12:11:01 +09:00
"pushed_at" : "2020-05-21T15:13:22Z" ,
2023-03-13 03:28:05 +09:00
"stargazers_count" : 52 ,
"watchers_count" : 52 ,
2022-11-08 09:17:44 +09:00
"has_discussions" : false ,
2022-01-20 21:14:25 +09:00
"forks_count" : 21 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [ ] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2022-01-20 21:14:25 +09:00
"forks" : 21 ,
2023-03-13 03:28:05 +09:00
"watchers" : 52 ,
2021-04-05 12:11:01 +09:00
"score" : 0
} ,
{
"id" : 269379345 ,
"name" : "CVE-2020-9484" ,
"full_name" : "qerogram\/CVE-2020-9484" ,
"owner" : {
"login" : "qerogram" ,
"id" : 29586629 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/29586629?v=4" ,
"html_url" : "https:\/\/github.com\/qerogram"
} ,
"html_url" : "https:\/\/github.com\/qerogram\/CVE-2020-9484" ,
"description" : "for Ubuntu 18.04, improve functions." ,
"fork" : false ,
"created_at" : "2020-06-04T14:19:12Z" ,
2022-02-23 21:15:23 +09:00
"updated_at" : "2022-02-23T07:05:46Z" ,
2021-04-05 12:11:01 +09:00
"pushed_at" : "2020-06-04T18:12:18Z" ,
"stargazers_count" : 1 ,
"watchers_count" : 1 ,
2022-11-08 09:17:44 +09:00
"has_discussions" : false ,
2021-04-05 12:11:01 +09:00
"forks_count" : 0 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [ ] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2021-04-05 12:11:01 +09:00
"forks" : 0 ,
"watchers" : 1 ,
"score" : 0
} ,
{
"id" : 269770630 ,
"name" : "CVE-2020-9484-Mass-Scan" ,
"full_name" : "osamahamad\/CVE-2020-9484-Mass-Scan" ,
"owner" : {
"login" : "osamahamad" ,
"id" : 59566963 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/59566963?v=4" ,
"html_url" : "https:\/\/github.com\/osamahamad"
} ,
"html_url" : "https:\/\/github.com\/osamahamad\/CVE-2020-9484-Mass-Scan" ,
"description" : "CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE " ,
"fork" : false ,
"created_at" : "2020-06-05T20:40:28Z" ,
2022-11-10 03:18:06 +09:00
"updated_at" : "2022-11-09T18:08:02Z" ,
2021-04-05 12:11:01 +09:00
"pushed_at" : "2020-06-05T21:04:43Z" ,
2022-11-10 03:18:06 +09:00
"stargazers_count" : 31 ,
"watchers_count" : 31 ,
2022-11-08 09:17:44 +09:00
"has_discussions" : false ,
2022-11-14 15:17:41 +09:00
"forks_count" : 15 ,
2021-09-14 06:12:57 +09:00
"allow_forking" : true ,
2021-10-07 06:13:51 +09:00
"is_template" : false ,
2022-06-29 03:20:29 +09:00
"web_commit_signoff_required" : false ,
2021-10-07 06:13:51 +09:00
"topics" : [ ] ,
2021-10-02 06:13:10 +09:00
"visibility" : "public" ,
2022-11-14 15:17:41 +09:00
"forks" : 15 ,
2022-11-10 03:18:06 +09:00
"watchers" : 31 ,
2021-04-05 12:11:01 +09:00
"score" : 0
2023-01-02 21:13:52 +09:00
} ,
{
"id" : 293086175 ,
"name" : "CVE-2020-9484-exploit" ,
"full_name" : "anjai94\/CVE-2020-9484-exploit" ,
"owner" : {
"login" : "anjai94" ,
"id" : 30573192 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/30573192?v=4" ,
"html_url" : "https:\/\/github.com\/anjai94"
} ,
"html_url" : "https:\/\/github.com\/anjai94\/CVE-2020-9484-exploit" ,
"description" : null ,
"fork" : false ,
"created_at" : "2020-09-05T13:56:51Z" ,
"updated_at" : "2022-10-13T07:18:49Z" ,
"pushed_at" : "2020-09-05T14:08:52Z" ,
"stargazers_count" : 6 ,
"watchers_count" : 6 ,
"has_discussions" : false ,
"forks_count" : 3 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 3 ,
"watchers" : 6 ,
"score" : 0
} ,
{
"id" : 325878746 ,
"name" : "CVE-2020-9484" ,
"full_name" : "PenTestical\/CVE-2020-9484" ,
"owner" : {
"login" : "PenTestical" ,
"id" : 57206134 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/57206134?v=4" ,
"html_url" : "https:\/\/github.com\/PenTestical"
} ,
"html_url" : "https:\/\/github.com\/PenTestical\/CVE-2020-9484" ,
"description" : null ,
"fork" : false ,
"created_at" : "2020-12-31T21:54:50Z" ,
2023-05-08 21:37:49 +09:00
"updated_at" : "2023-05-08T08:21:47Z" ,
2023-01-02 21:13:52 +09:00
"pushed_at" : "2022-04-16T14:22:27Z" ,
2023-05-08 21:37:49 +09:00
"stargazers_count" : 22 ,
"watchers_count" : 22 ,
2023-01-02 21:13:52 +09:00
"has_discussions" : false ,
"forks_count" : 7 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 7 ,
2023-05-08 21:37:49 +09:00
"watchers" : 22 ,
2023-01-02 21:13:52 +09:00
"score" : 0
2023-01-07 09:35:14 +09:00
} ,
2023-03-14 21:29:39 +09:00
{
"id" : 329004194 ,
"name" : "CVE-2020-9484-Scanner" ,
"full_name" : "DanQMoo\/CVE-2020-9484-Scanner" ,
"owner" : {
"login" : "DanQMoo" ,
"id" : 29651956 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/29651956?v=4" ,
"html_url" : "https:\/\/github.com\/DanQMoo"
} ,
"html_url" : "https:\/\/github.com\/DanQMoo\/CVE-2020-9484-Scanner" ,
"description" : "A smol bash script I threw together pretty quickly to scan for vulnerable versions of the Apache Tomcat RCE. I'll give it some love when I have the time. " ,
"fork" : false ,
"created_at" : "2021-01-12T14:00:00Z" ,
"updated_at" : "2022-04-17T09:09:57Z" ,
"pushed_at" : "2020-06-10T07:08:17Z" ,
"stargazers_count" : 0 ,
"watchers_count" : 0 ,
"has_discussions" : false ,
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
"watchers" : 0 ,
"score" : 0
} ,
2023-01-07 09:35:14 +09:00
{
"id" : 333238894 ,
"name" : "CVE-2020-9484" ,
"full_name" : "AssassinUKG\/CVE-2020-9484" ,
"owner" : {
"login" : "AssassinUKG" ,
"id" : 5285547 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/5285547?v=4" ,
"html_url" : "https:\/\/github.com\/AssassinUKG"
} ,
"html_url" : "https:\/\/github.com\/AssassinUKG\/CVE-2020-9484" ,
"description" : null ,
"fork" : false ,
"created_at" : "2021-01-26T22:51:30Z" ,
"updated_at" : "2022-10-10T21:55:08Z" ,
"pushed_at" : "2021-02-10T00:01:45Z" ,
"stargazers_count" : 5 ,
"watchers_count" : 5 ,
"has_discussions" : false ,
"forks_count" : 4 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 4 ,
"watchers" : 5 ,
"score" : 0
} ,
{
"id" : 337782636 ,
"name" : "CVE-2020-9484" ,
"full_name" : "VICXOR\/CVE-2020-9484" ,
"owner" : {
"login" : "VICXOR" ,
"id" : 43370621 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/43370621?v=4" ,
"html_url" : "https:\/\/github.com\/VICXOR"
} ,
"html_url" : "https:\/\/github.com\/VICXOR\/CVE-2020-9484" ,
"description" : "POC for CVE-2020-9484" ,
"fork" : false ,
"created_at" : "2021-02-10T16:27:07Z" ,
2023-03-16 03:30:24 +09:00
"updated_at" : "2023-03-15T15:08:49Z" ,
2023-01-07 09:35:14 +09:00
"pushed_at" : "2021-02-10T16:55:37Z" ,
2023-03-16 03:30:24 +09:00
"stargazers_count" : 7 ,
"watchers_count" : 7 ,
2023-01-07 09:35:14 +09:00
"has_discussions" : false ,
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [
"apache" ,
"exploit" ,
"rce" ,
"tomcat"
] ,
"visibility" : "public" ,
"forks" : 0 ,
2023-03-16 03:30:24 +09:00
"watchers" : 7 ,
2023-01-07 09:35:14 +09:00
"score" : 0
} ,
{
"id" : 343388829 ,
"name" : "CVE-2020-9484" ,
"full_name" : "DXY0411\/CVE-2020-9484" ,
"owner" : {
"login" : "DXY0411" ,
"id" : 42259364 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/42259364?v=4" ,
"html_url" : "https:\/\/github.com\/DXY0411"
} ,
"html_url" : "https:\/\/github.com\/DXY0411\/CVE-2020-9484" ,
"description" : null ,
"fork" : false ,
"created_at" : "2021-03-01T11:16:04Z" ,
"updated_at" : "2021-03-08T10:02:52Z" ,
"pushed_at" : "2021-03-08T10:02:50Z" ,
"stargazers_count" : 0 ,
"watchers_count" : 0 ,
"has_discussions" : false ,
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
"watchers" : 0 ,
"score" : 0
} ,
{
"id" : 368539603 ,
"name" : "CVE-2020-9484" ,
"full_name" : "RepublicR0K\/CVE-2020-9484" ,
"owner" : {
"login" : "RepublicR0K" ,
"id" : 73670332 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/73670332?v=4" ,
"html_url" : "https:\/\/github.com\/RepublicR0K"
} ,
"html_url" : "https:\/\/github.com\/RepublicR0K\/CVE-2020-9484" ,
"description" : "Apache Tomcat RCE (CVE-2020-9484)" ,
"fork" : false ,
"created_at" : "2021-05-18T13:26:18Z" ,
2023-01-10 15:30:02 +09:00
"updated_at" : "2023-01-10T03:22:47Z" ,
2023-01-07 09:35:14 +09:00
"pushed_at" : "2021-05-18T13:27:11Z" ,
2023-01-10 15:30:02 +09:00
"stargazers_count" : 4 ,
"watchers_count" : 4 ,
2023-01-07 09:35:14 +09:00
"has_discussions" : false ,
2023-03-29 21:32:12 +09:00
"forks_count" : 3 ,
2023-01-07 09:35:14 +09:00
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
2023-03-29 21:32:12 +09:00
"forks" : 3 ,
2023-01-10 15:30:02 +09:00
"watchers" : 4 ,
2023-01-07 09:35:14 +09:00
"score" : 0
} ,
2023-03-24 15:30:34 +09:00
{
"id" : 458246235 ,
"name" : "CVE-2020-9484" ,
"full_name" : "ColdFusionX\/CVE-2020-9484" ,
"owner" : {
"login" : "ColdFusionX" ,
"id" : 8522240 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/8522240?v=4" ,
"html_url" : "https:\/\/github.com\/ColdFusionX"
} ,
"html_url" : "https:\/\/github.com\/ColdFusionX\/CVE-2020-9484" ,
"description" : "POC - Apache Tomcat Deserialization Vulnerability (CVE-2020-9484)" ,
"fork" : false ,
"created_at" : "2022-02-11T15:45:10Z" ,
2023-03-24 21:32:21 +09:00
"updated_at" : "2023-03-24T09:17:42Z" ,
2023-03-24 15:30:34 +09:00
"pushed_at" : "2022-02-11T18:02:52Z" ,
2023-03-24 21:32:21 +09:00
"stargazers_count" : 4 ,
"watchers_count" : 4 ,
2023-03-24 15:30:34 +09:00
"has_discussions" : false ,
"forks_count" : 2 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [
"cve-2020-9484" ,
"deserialization" ,
"docker" ,
"exploit" ,
"rce" ,
"serialization" ,
"tomcat"
] ,
"visibility" : "public" ,
"forks" : 2 ,
2023-03-24 21:32:21 +09:00
"watchers" : 4 ,
2023-03-24 15:30:34 +09:00
"score" : 0
} ,
2023-01-07 09:35:14 +09:00
{
"id" : 565892834 ,
"name" : "CVE-2020-9484_Exploit" ,
2023-02-15 23:15:57 +09:00
"full_name" : "d3fudd\/CVE-2020-9484_Exploit" ,
2023-01-07 09:35:14 +09:00
"owner" : {
2023-02-15 23:15:57 +09:00
"login" : "d3fudd" ,
2023-01-07 09:35:14 +09:00
"id" : 76706456 ,
"avatar_url" : "https:\/\/avatars.githubusercontent.com\/u\/76706456?v=4" ,
2023-02-15 23:15:57 +09:00
"html_url" : "https:\/\/github.com\/d3fudd"
2023-01-07 09:35:14 +09:00
} ,
2023-02-15 23:15:57 +09:00
"html_url" : "https:\/\/github.com\/d3fudd\/CVE-2020-9484_Exploit" ,
2023-01-07 09:35:14 +09:00
"description" : "Exploit for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE" ,
"fork" : false ,
"created_at" : "2022-11-14T14:48:30Z" ,
2023-05-08 03:28:28 +09:00
"updated_at" : "2023-05-07T14:19:22Z" ,
2023-04-18 03:30:54 +09:00
"pushed_at" : "2023-04-17T14:52:50Z" ,
2023-05-08 03:28:28 +09:00
"stargazers_count" : 7 ,
"watchers_count" : 7 ,
2023-01-07 09:35:14 +09:00
"has_discussions" : false ,
"forks_count" : 0 ,
"allow_forking" : true ,
"is_template" : false ,
"web_commit_signoff_required" : false ,
"topics" : [ ] ,
"visibility" : "public" ,
"forks" : 0 ,
2023-05-08 03:28:28 +09:00
"watchers" : 7 ,
2023-01-07 09:35:14 +09:00
"score" : 0
2020-12-31 06:09:58 +09:00
}
]