id: kubernetes-version info: name: Kubernetes Version Exposure author: raesene,idealphase severity: info description: Searches for exposed Kubernetes API servers which return version information unauthenticated. For Google Kubernetes Engine (GKE) and Amazon Elastic Kubernetes Service (EKS) this template will extract default patch version for you. reference: - https://cloud.google.com/kubernetes-engine/docs/release-notes - https://docs.aws.amazon.com/eks/latest/userguide/kubernetes-versions.html metadata: max-request: 1 shodan-query: product:"Kubernetes" version:"1.21.5-eks-bc4871b" tags: tech,k8s,kubernetes,devops http: - method: GET path: - "{{BaseURL}}/version" matchers: - type: word words: - "gitVersion" - "goVersion" - "platform" condition: and extractors: - type: json json: - '.gitVersion' # digest: 4b0a00483046022100d2d5793c322f4c5de81f7028dc4e7fc7bf62b952be440f81570cbe485c768639022100fab2e5accb6d5e3483523e9c3f594fe0c03fa387cdaace1d1e7eadb129892117:922c64590222798bb761d5b6d8e72950