id: spark-webui-unauth.yaml info: name: Unauthenticated Spark WebUI author: princechaddha severity: medium reference: https://github.com/vulhub/vulhub/tree/master/spark/unacc tags: spark,unauth requests: - method: GET path: - "{{BaseURL}}/" matchers-condition: and matchers: - type: status status: - 200 - type: word words: - "Spark Master at spark://" - "<strong>URL:</strong>" part: body condition: and