diff --git a/misconfiguration/kubernetes-exposed-metrics.yaml b/misconfiguration/kubernetes-metrics.yaml similarity index 62% rename from misconfiguration/kubernetes-exposed-metrics.yaml rename to misconfiguration/kubernetes-metrics.yaml index f33fd429b0..ff9910a0cd 100644 --- a/misconfiguration/kubernetes-exposed-metrics.yaml +++ b/misconfiguration/kubernetes-metrics.yaml @@ -1,24 +1,29 @@ -id: kubernetes-exposed-metrics +id: kubernetes-metrics + info: name: Detect Kubernetes Exposed Metrics author: pussycat0x severity: low description: Information Disclosure of Garbage Collection - tags: kubernetes,exposure, metrics + tags: kubernetes,exposure,devops + reference: https://kubernetes.io/docs/concepts/cluster-administration/system-metrics/#metrics-in-kubernetes + requests: - method: GET path: - - "{{BaseURL}}:8080/metrics" + - "{{BaseURL}}/metrics" + matchers-condition: and matchers: - type: word part: body + condition: and words: - "namespace" - "HELP" - "TYPE" - "kube" - condition: and + - type: status status: - 200 \ No newline at end of file