Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3683 | Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a proof-of-work challenge to discourage scraping from multiple IP addresses. Anubis allows attackers to bypass the bot protection by requesting a challenge, formulates any nonce (such as 42069), and then passes the challenge with difficulty zero. Commit e09d0226a628f04b1d80fd83bee777894a45cd02 fixes this behavior by not using a client-specified difficulty value. |
Tue, 28 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jan 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a proof-of-work challenge to discourage scraping from multiple IP addresses. Anubis allows attackers to bypass the bot protection by requesting a challenge, formulates any nonce (such as 42069), and then passes the challenge with difficulty zero. Commit e09d0226a628f04b1d80fd83bee777894a45cd02 fixes this behavior by not using a client-specified difficulty value. | |
| Title | Anubis has a bot protection bypass when a sophisticated attacker asks to pass a challenge of difficulty 0 | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-28T15:18:44.746Z
Reserved: 2025-01-20T15:18:26.991Z
Link: CVE-2025-24369
Updated: 2025-01-28T14:47:41.051Z
Status : Deferred
Published: 2025-01-27T23:15:11.310
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24369
No data.
OpenCVE Enrichment
No data.
EUVD