漏洞描述
Public Pantheon YAML Configuration Files might include sensitive info
id: pantheon-upstream
info:
name: Pantheon upstream.yml Disclosure
author: DhiyaneshDK
severity: low
description: Public Pantheon YAML Configuration Files might include sensitive info
reference:
- https://pantheon.io/docs/pantheon-yml
metadata:
verified: true
max-request: 1
google-query: intitle:"index of" "pantheon.upstream.yml"
tags: exposure,devops,patheon,config,files,vuln
http:
- method: GET
path:
- "{{BaseURL}}/pantheon.upstream.yml"
matchers-condition: and
matchers:
- type: word
words:
- 'database:'
- 'protected_web_paths:'
condition: and
- type: status
status:
- 200
# digest: 4a0a004730450220660c8958e513b5d66d2b68d11d52467a9acf906f6764ba2c071eb388a6e957ee022100c5870f9bcb16138d529574feece00e3f0a8b21fa77aeb9fc7ec1096e2aabc8e4:922c64590222798bb761d5b6d8e72950