diff --git a/misconfiguration/unauth-netdata.yaml b/misconfiguration/unauth-netdata.yaml new file mode 100644 index 0000000000..9dd7e429ca --- /dev/null +++ b/misconfiguration/unauth-netdata.yaml @@ -0,0 +1,27 @@ +id: unauth-netdata +info: + name: Unauthenticated Netdata + author: dhiyaneshDk + severity: medium + reference: https://github.com/netdata/netdata + tags: netdata,unauth + +requests: + - method: GET + path: + - "{{BaseURL}}/api/v1/data?chart=system.cpu&format=json&points=125&group=average>ime=0&options=ms%7Cflip%7Cjsonwrap%7Cnonzero&after=-120&dimensions=iowait" + matchers-condition: and + matchers: + - type: status + status: + - 200 + - type: word + words: + - "view_update_every" + - "dimensions" + part: body + - type: word + words: + - "application/json" + part: header + condition: and