漏洞描述
Detects if the config page of the Apache Hive is exposed.
id: apache-hive-config
info:
name: Apache Hive Configuration - Exposure
author: icarot
severity: medium
description: |
Detects if the config page of the Apache Hive is exposed.
reference:
- 'https://github.com/apache/hive'
classification:
cpe: cpe:2.3:a:apache:hive:4.6.0:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: apache
product: hive
shodan-query: title:"HiveServer2"
tags: apache,hive,config,exposure,vuln
http:
- method: GET
path:
- "{{BaseURL}}/conf"
matchers-condition: and
matchers:
- type: word
part: body
words:
- 'hive.conf.'
- '<configuration>'
condition: and
- type: status
status:
- 200
# digest: 4b0a00483046022100fd18fc42068949c8f5b6e829f5a7190012ef92a02556b4b1c00e749339a6381f022100f43826823edbb5548fce6bac8f49c3e69201ec672ef4a9446ab855ee8537174d:922c64590222798bb761d5b6d8e72950