id: exposed-kafdrop info: name: Publicly exposed Kafdrop Interface author: dhiyaneshDk severity: low metadata: max-request: 1 tags: exposure,misconfig,kafdrop http: - method: GET path: - '{{BaseURL}}' matchers: - type: word words: - "Kafdrop: Broker List" - "Kafka Cluster Overview" condition: and # digest: 4b0a00483046022100bc8e0a790e3429100da20b665cce8559d914e768d4726719ba6cf86071870bc50221009ccbc7713b7b905a1d750b1ff96a7a9448097827f637aeaaff89f73e35e90f9c:922c64590222798bb761d5b6d8e72950