nuclei-templates/http/misconfiguration/artifactory-anonymous-deplo...

36 lines
853 B
YAML
Raw Normal View History

id: artifactory-anonymous-deploy
info:
2021-06-07 19:03:06 +00:00
name: Artifactory anonymous deploy
author: panch0r3d
severity: high
2024-01-03 06:08:41 +00:00
description: Artifactory anonymous repo is exposed.
reference:
- https://www.errno.fr/artifactory/Attacking_Artifactory.html
metadata:
max-request: 1
2023-10-14 11:27:55 +00:00
tags: artifactory,misconfig
http:
- method: GET
path:
- "{{BaseURL}}/artifactory/ui/repodata?deploy=true"
2021-06-07 19:03:06 +00:00
matchers-condition: and
matchers:
2021-06-07 19:03:06 +00:00
- type: word
words:
- '"repoKey"'
part: body
2021-06-07 19:03:06 +00:00
- type: status
status:
- 200
- type: word
words:
- "application/json"
2023-10-14 11:27:55 +00:00
part: header
# digest: 490a0046304402201619c079977053273ab56c30fcb02cddb917163e9aaf88c27179e9db0fb30b4602203c3db1d209d5fc347ae8dca987107a36bc40abd21a86ae80dde852bfc85ea200:922c64590222798bb761d5b6d8e72950