id: yarn-manager-exposure info: name: Apache Yarn ResourceManager Exposure / Unauthenticated Access author: pd-team severity: low requests: - method: GET path: - '{{BaseURL}}/cluster/cluster' matchers: - type: word words: - 'hadoop' - 'resourcemanager' - 'logged in as: dr.who' condition: and