id: apache-storm-unauth info: name: Apache Storm Unauth author: pikpikcu severity: medium reference: - https://storm.apache.org/releases/current/STORM-UI-REST-API.html tags: apache,unauth,misconfig requests: - method: GET path: - '{{BaseURL}}/api/v1/cluster/summary' matchers-condition: and matchers: - type: word part: body words: - '"totalMem":' - '"stormVersion":' condition: and - type: status status: - 200