id: docker-cloud info: name: Docker Cloud Yaml - File Disclosure author: DhiyaneshDK severity: medium description: Docker cloud internal yaml file is exposed. reference: https://www.exploit-db.com/ghdb/7959 metadata: verified: true max-request: 1 google-query: intitle:"index of" "docker-cloud.yml" tags: exposure,cloud,devops,docker,files http: - method: GET path: - "{{BaseURL}}/docker-cloud.yml" matchers-condition: and matchers: - type: regex regex: - '(?m)^ image:' - '(?m)^ ports:' condition: and - type: word part: header words: - "application/json" - "text/html" negative: true condition: or - type: status status: - 200 # digest: 4b0a00483046022100f477732592a1da454636ad97ec7b328366d3a6d13e9dce509332ee2a6b16bc00022100cbc5e508462ae15fdbb0fcca941831f52dc665b8ba50c9b24e7e60a53e65436a:922c64590222798bb761d5b6d8e72950