jboss-seam-debug-page: Jboss Seam Debug Page Enabled

日期: 2025-08-01 | 影响软件: jboss seam debug page | POC: 已公开

漏洞描述

Jboss Seam Debug Page was exposed.

PoC代码[已公开]

id: jboss-seam-debug-page

info:
  name: Jboss Seam Debug Page Enabled
  author: dhiyaneshDK
  severity: medium
  description: Jboss Seam Debug Page was exposed.
  reference:
    - https://github.com/jaeles-project/jaeles-signatures/blob/master/common/jboss-seam-debug-page.yaml
  metadata:
    max-request: 1
  tags: jboss,logs,exposure,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/debug.seam"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "SeamDebugPage"
          - "org.jboss.seam"
        condition: and

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100c1eaed345d5725fd1af05ad5a0e7746975c651194c81d6942699fe60691940160221008a643d084113373bf04e3b3cffa8b9332647f76a9c81a796365e741605491aa8:922c64590222798bb761d5b6d8e72950