漏洞描述
Dockerrun AWS configuration page was detected.
id: amazon-docker-config
info:
name: Dockerrun AWS Configuration Page - Detect
author: pdteam
severity: medium
description: Dockerrun AWS configuration page was detected.
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss-score: 5.3
cwe-id: CWE-200
metadata:
max-request: 1
tags: config,exposure,aws,devops,vuln
http:
- method: GET
path:
- '{{BaseURL}}/Dockerrun.aws.json'
matchers:
- type: word
words:
- 'AWSEBDockerrunVersion'
- 'containerDefinitions'
condition: and
# digest: 4a0a00473045022100a1f5b7d79ba30f31c57c7869b79fbab25296ef959c5c766aafcb496c91b5a10e022076fd85053f04e3844bc11a95ca8117baf421b8987719d46d77ac160e17c8ef06:922c64590222798bb761d5b6d8e72950