漏洞描述
Vercel Config file is exposed.
id: vercel-config-file
info:
name: Vercel Config File - File Disclosure
author: DhiyaneshDk
severity: low
description: |
Vercel Config file is exposed.
reference:
- https://vercel.com/docs/project-configuration
metadata:
verified: true
max-request: 1
shodan-query: html:"vercel.json"
tags: exposure,files,vercel,vuln
http:
- method: GET
path:
- '{{BaseURL}}/vercel.json'
matchers-condition: and
matchers:
- type: word
part: body
words:
- '"builds": ['
- '"routes": ['
- '"use": "@vercel'
condition: and
case-insensitive: true
- type: word
part: content_type
words:
- 'application/json'
# digest: 4a0a00473045022100cc20b118d76edf90206a4ad572895f15af43cc72a5f03056411cdcbd85fcdeb102206448b3d93ea06a1b0e4f1829609aabd42aae1aea79f3b1070c37321267c2013b:922c64590222798bb761d5b6d8e72950