漏洞描述
Azure Resource Manager deploy file is disclosed.
id: azuredeploy-json
info:
name: Azure Resource Manager Template - File Exposure
author: DhiyaneshDk
severity: medium
description: Azure Resource Manager deploy file is disclosed.
reference:
- https://learn.microsoft.com/en-us/azure/azure-resource-manager/templates/parameter-files
- https://learn.microsoft.com/en-us/azure/azure-resource-manager/templates/template-tutorial-use-template-reference?tabs=CLI
metadata:
verified: true
max-request: 1
fofa-query: body="azuredeploy.json"
tags: azure,exposure,files,vuln
http:
- method: GET
path:
- "{{BaseURL}}/azuredeploy.json"
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"$schema":'
- '"contentVersion":'
- '"parameters":'
condition: and
- type: word
part: header
words:
- "application/json"
- type: status
status:
- 200
# digest: 4a0a0047304502210089b231c195f8a16ac9c0f52087a3f24c7e3aa78c9f624cbb2f8b6380f261dde40220458db4f188f535319c2e745f3511d551005ddd8cf5b617b836fbf35009f396c9:922c64590222798bb761d5b6d8e72950