azuredeploy-json: Azure Resource Manager Template - File Exposure

日期: 2025-08-01 | 影响软件: azuredeploy-json | POC: 已公开

漏洞描述

Azure Resource Manager deploy file is disclosed.

PoC代码[已公开]

id: azuredeploy-json

info:
  name: Azure Resource Manager Template - File Exposure
  author: DhiyaneshDk
  severity: medium
  description: Azure Resource Manager deploy file is disclosed.
  reference:
    - https://learn.microsoft.com/en-us/azure/azure-resource-manager/templates/parameter-files
    - https://learn.microsoft.com/en-us/azure/azure-resource-manager/templates/template-tutorial-use-template-reference?tabs=CLI
  metadata:
    verified: true
    max-request: 1
    fofa-query: body="azuredeploy.json"
  tags: azure,exposure,files,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/azuredeploy.json"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"$schema":'
          - '"contentVersion":'
          - '"parameters":'
        condition: and

      - type: word
        part: header
        words:
          - "application/json"

      - type: status
        status:
          - 200
# digest: 4a0a0047304502210089b231c195f8a16ac9c0f52087a3f24c7e3aa78c9f624cbb2f8b6380f261dde40220458db4f188f535319c2e745f3511d551005ddd8cf5b617b836fbf35009f396c9:922c64590222798bb761d5b6d8e72950