dockerfile-hidden-disclosure: Dockerfile - Detect

日期: 2025-08-01 | 影响软件: Dockerfile | POC: 已公开

漏洞描述

Dockerfile was detected.

PoC代码[已公开]

id: dockerfile-hidden-disclosure

info:
  name: Dockerfile - Detect
  author: dhiyaneshDk
  severity: medium
  description: Dockerfile was detected.
  reference:
    - https://github.com/detectify/ugly-duckling/blob/master/modules/crowdsourced/dockerfile-hidden-disclosure.json
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cwe-id: CWE-200
  metadata:
    max-request: 3
  tags: exposure,config,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/.dockerfile"
      - "{{BaseURL}}/.Dockerfile"
      - "{{BaseURL}}/Dockerfile"

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - '^(?:FROM(?:CACHE)?|RUN|ADD|WORKDIR|ENV|EXPOSE|\#)\s+[ -~]+'
        part: body

      - type: status
        status:
          - 200

      - type: word
        part: header
        words:
          - "text/html"
        negative: true
# digest: 4a0a004730450220090331a4e7e4085299a56c51a9860b0b97e9fa5d2ddd38996b24b157b50d2773022100dc5ea83df625877f375e4cd7dbfefc5bd792901c7d880c974eb0d736c7512e3a:922c64590222798bb761d5b6d8e72950