From efc7f6b0218d4ce2a2105866b7c1ec81c546df70 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Sat, 19 Aug 2023 10:55:59 +0530 Subject: [PATCH] updated metadata --- http/misconfiguration/unauth-redis-insight.yaml | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/http/misconfiguration/unauth-redis-insight.yaml b/http/misconfiguration/unauth-redis-insight.yaml index f4f62427d3..12b62f3219 100644 --- a/http/misconfiguration/unauth-redis-insight.yaml +++ b/http/misconfiguration/unauth-redis-insight.yaml @@ -4,17 +4,15 @@ info: name: RedisInsight - Unauthenticated Access author: ggranjus severity: high - description: RedisInsight was able to be accessed because no authentication was required. - reference: https://redis.com/redis-enterprise/redis-insight/ - classification: - cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N - cvss-score: 0.0 - cwe-id: CWE-200 + description: | + RedisInsight was able to be accessed because no authentication was required. + reference: + - https://redis.com/redis-enterprise/redis-insight/ metadata: verified: 'true' - shodan-query: http.title:RedisInsight + shodan-query: title:"RedisInsight" max-request: 1 - tags: redis,redisinsight,unauth + tags: redis,redisinsight,unauth,misconfig http: - method: GET @@ -26,6 +24,7 @@ http: - type: word words: - "RedisInsight" + - type: status status: - 200