id: unauth-kubecost info: name: KubeCost - Unauthenticated Dashboard Exposure author: pussycat0x severity: medium reference: https://www.facebook.com/photo?fbid=470414125129112&set=pcb.470413798462478 metadata: verified: true max-request: 1 shodan-query: title:kubecost tags: misconfig,exposure,unauth,kubecost http: - method: GET path: - '{{BaseURL}}/overview.html' matchers-condition: and matchers: - type: word words: - "Cluster Overview | Kubecost" - "Kubecost" condition: or - type: word part: header words: - text/html - type: status status: - 200 # digest: 4a0a00473045022019b896ecf523a7707073ea5039d13a1d528ad90c75da68987b0ae04512872fdf022100de3a81038a7dcd92cfed206b88c8e764b83715e9343e32090122f5e55d0deec2:922c64590222798bb761d5b6d8e72950