social @ 2024-04-17

The watchTowr folks published an in-depth article today covering the Palo Alto Networks unauthenticated RCE at: labs.watchtowr.com/palo-alto-p

Even more impressive is they also disclosed a zero-day directory traversal vulnerability in the gorilla/sessions package (used far and wide). The gorilla vulnerability only applies to code using the FilesystemStore, but it is still likely to impact a huge range of products and services. A pull request to fix this is open at github.com/gorilla/sessions/pu

Huge thanks to @alizthehax0r and the watchTowr team as well as @moloch of Bishop Fox for co-discovery (and providing a fix for) of the gorilla/sessions bug.