id: ruby-rail-storage info: name: Ruby on Rails storage.yml File Disclosure author: DhiyaneshDK severity: low description: Ruby on Rails storage.yml file is disclosed. classification: cpe: cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* metadata: verified: true max-request: 4 vendor: rubyonrails product: rails google-query: intitle:"index of" storage.yml tags: exposure,ruby,devops,files http: - method: GET path: - "{{BaseURL}}/storage.yml" - "{{BaseURL}}/config/storage.yml" - "{{BaseURL}}/ruby/config/storage.yml" - "{{BaseURL}}/railsapp/config/storage.yml" stop-at-first-match: true matchers-condition: and matchers: - type: word words: - 'service:' - 'local:' condition: and - type: word part: header words: - "application/json" - "text/html" negative: true condition: and - type: status status: - 200 # digest: 4a0a00473045022100b584d87cec7b192d8d5480428fa7bfb9636e83c80bdce0712cda45b4789864be02202a3398bb22947627e3beb69438b9a2113a2a277ae304567cd0363ccd2e1abfa0:922c64590222798bb761d5b6d8e72950