diff --git a/misconfiguration/apache-druid-unauth.yaml b/misconfiguration/apache-druid-unauth.yaml new file mode 100644 index 0000000000..2be397b3a5 --- /dev/null +++ b/misconfiguration/apache-druid-unauth.yaml @@ -0,0 +1,30 @@ +id: apache-druid-unauth + +info: + name: Apache Druid Unauth + author: DhiyaneshDk + severity: low + metadata: + verified: true + shodan-query: title:"Apache Druid" + tags: druid,unauth + +requests: + - method: GET + path: + - '{{BaseURL}}/unified-console.html' + + matchers-condition: and + matchers: + + - type: word + words: + - 'Apache Druid' + - type: word + words: + - 'text/html' + part: header + + - type: status + status: + - 200