2021-05-03 06:36:21 +00:00
id : kubernetes-version
info :
name : Kubernetes Version Exposure
2022-03-16 22:19:02 +00:00
author : raesene,idealphase
2022-04-22 10:38:41 +00:00
severity : info
description : Searches for exposed Kubernetes API servers which return version information unauthenticated. For Google Kubernetes Engine (GKE) and Amazon Elastic Kubernetes Service (EKS) this template will extract
default patch version for you.
2022-03-16 22:19:02 +00:00
reference :
- https://cloud.google.com/kubernetes-engine/docs/release-notes
- https://docs.aws.amazon.com/eks/latest/userguide/kubernetes-versions.html
metadata :
2023-04-28 08:11:21 +00:00
max-request : 1
2022-03-16 22:19:02 +00:00
shodan-query : product:"Kubernetes" version:"1.21.5-eks-bc4871b"
2021-05-26 21:16:26 +00:00
tags : tech,k8s,kubernetes,devops
2021-05-03 06:36:21 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-05-03 06:36:21 +00:00
- method : GET
path :
- "{{BaseURL}}/version"
matchers :
- type : word
words :
- "gitVersion"
- "goVersion"
- "platform"
2021-05-26 21:16:26 +00:00
condition : and
2022-03-16 22:19:02 +00:00
extractors :
- type : json
json :
- '.gitVersion'