CVE-2024-2053 affects the Artica Proxy administrative web application. According to the provided content, the application will deserialize arbitrary PHP objects supplied by unauthenticated users, which can lead to code execution in the context of the web server process as the "www-data" user. The issue was demonstrated on version 4.50. The same content also states that the application's protections intended to prevent local file inclusion can be bypassed, allowing unauthenticated users to request arbitrary files and have them returned with the access rights of the "www-data" user. Based on the supplied information, the primary weakness is unsafe deserialization of untrusted data, with an additional file inclusion/path restriction bypass condition described.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python3 exploit script (CVE-2024-2053.py) targeting Artica Proxy (versions 4.40 and 4.50) for CVE-2024-2053, a Local File Inclusion (LFI) vulnerability that can be escalated to Remote Code Execution (RCE) via log poisoning. The exploit works by first confirming LFI via known file paths (e.g., /etc/passwd), then injecting PHP payloads into various server logs (such as Apache, Nginx, or Lighttpd access logs) using multiple HTTP headers and parameters. It then attempts to include these poisoned logs through the vulnerable endpoint, causing the server to write a PHP webshell to the web root. The script supports proxying, SSL verification toggling, and verbose output. The repository also includes a YAML file describing the vulnerability for detection purposes, a README with usage instructions and technical details, a requirements.txt for dependencies, and standard licensing. The main attack vector is network-based, exploiting a web application endpoint. The exploit is operational, providing a working webshell if successful, and is not part of a larger exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.