id: active-admin-exposure info: name: ActiveAdmin Admin Dasboard Exposure author: pdteam severity: info description: An ActiveAdmin Admin dashboard was discovered. reference: - https://activeadmin.info/ classification: cwe-id: CWE-200 metadata: max-request: 1 tags: panel,activeadmin http: - method: GET path: - '{{BaseURL}}/admin/login' matchers: - type: word words: - "active_admin_content" - "active_admin-" condition: and # digest: 4a0a0047304502210093a1e17e2496cbac4f37f6b4ea056f35f5cc2806c6cc54fa10841f7373287542022051cb9601cde6623215edc0aacb5f78ad1cd753a0eff94ce49f8155914d30031d:922c64590222798bb761d5b6d8e72950