doris-dashboard: Doris Dashboard - Exposed

日期: 2025-08-01 | 影响软件: Doris Dashboard | POC: 已公开

漏洞描述

Unauthorized access to the Doris Dashboard.

PoC代码[已公开]

id: doris-dashboard

info:
  name: Doris Dashboard - Exposed
  author: ritikchaddha
  severity: medium
  description: Unauthorized access to the Doris Dashboard.
  metadata:
    verified: true
    max-request: 1
    shodan-query: http.favicon.hash:24048806
  tags: doris,exposure,unauth,logs,misconfig,discovery

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'Doris</title>'
          - 'CPU Profile</a>'
          - 'Heap Profile</a>'
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a004730450220172eb2b8bc1354ad132cca316514fd0e782cb417416c985328652864d7686809022100d081d60ebb91ef72bebb55059bf133a97e3c6d3de0997a14a4f2fc41fdc25c54:922c64590222798bb761d5b6d8e72950