id: unauth-cluster-trino info: name: Cluster Overview - Unauthenticated Dashboard Exposure author: tess severity: medium metadata: verified: true max-request: 1 shodan-query: http.title:"Cluster Overview - Trino" tags: cluster,unauth,trino,misconfig http: - method: POST path: - "{{BaseURL}}/ui/login" headers: Content-Type: application/x-www-form-urlencoded body: | username={{randstr}}&password=&redirectPath= cookie-reuse: true redirects: true matchers-condition: and matchers: - type: word part: body words: - 'Cluster Overview' - 'Query Details' condition: and - type: status status: - 200 # digest: 4a0a00473045022100aeaab57c32cfbb260ff54f583e370a2db7dce3d4ad67c4c0c62b4eba16921f9202200c5c3bb1919b51093e76fdf89ab455b0807f32997ed7a0ddf5aaf7438db82764:922c64590222798bb761d5b6d8e72950