该脚本是一个基于 Python 的 PoC,用于远程检测 CVE-2025-24514 漏洞(通过 ingress-nginx 的 auth-url 注入操纵 NGINX 配置并可能导致 RCE)。
ingress-nginx 通过 nginx.ingress.kubernetes.io/auth-url 注解进行 NGINX 配置意外注入 的漏洞。/;error_log /dev/stdout;),则 NGINX 配置文件被篡改,可能导致任意命令执行或信息泄露。auth-url 配置error_log、auth-url 字符串判断是否存在漏洞colorama 进行彩色输出需要 Python 3.x 环境。
bash pip install requests colorama```
bash python cve_2025_24514_remote_poc.py
[=] CVE-2025-24514 远程漏洞检测 PoC 开始 =
[?] 请输入目标服务器 URL/IP (例如 http://192.168.0.0): http://192.168.0.0 [+] 正在向目标发送恶意请求: http://192.168.0.0 [+] HTTP 响应码: 200 [+] 响应内容 (前300字):
Welcome... [!!!] 漏洞可能性非常高:怀疑 NGINX 配置泄露本 PoC 正常运行需满足以下部分条件:
auth-url 注解未进行过滤处理auth-url、auth-signin 注解应用用户输入验证如有 Bug 报告或建议,请通过 email 或 PR 提交。
This project is licensed under the MIT License - see the LICENSE file for details. Copyright (c) 2025 KimJuhyeong95