id: apache-storm-unauth info: name: Apache Storm Unauth author: pikpikcu severity: medium reference: - https://storm.apache.org/releases/current/STORM-UI-REST-API.html metadata: max-request: 1 tags: apache,unauth,misconfig http: - method: GET path: - '{{BaseURL}}/api/v1/cluster/summary' matchers-condition: and matchers: - type: word part: body words: - '"totalMem":' - '"stormVersion":' condition: and - type: status status: - 200 # digest: 490a0046304402206445294e1d237514858065f44d0ca332874876a4071b4163c436a74f803abb6c022066822b6f0d9f4fa25b39da6bec4db4aef6067a7a6d78391697a8022dc4131691:922c64590222798bb761d5b6d8e72950