nuclei-templates/technologies/kubernetes/kubernetes-version.yaml

32 lines
921 B
YAML

id: kubernetes-version
info:
name: Kubernetes Version Exposure
author: raesene,idealphase
description: Searches for exposed Kubernetes API servers which return version information unauthenticated. For Google Kubernetes Engine (GKE) and Amazon Elastic Kubernetes Service (EKS) this template will extract default patch version for you.
reference:
- https://cloud.google.com/kubernetes-engine/docs/release-notes
- https://docs.aws.amazon.com/eks/latest/userguide/kubernetes-versions.html
severity: info
metadata:
shodan-query: product:"Kubernetes" version:"1.21.5-eks-bc4871b"
tags: tech,k8s,kubernetes,devops
requests:
- method: GET
path:
- "{{BaseURL}}/version"
matchers:
- type: word
words:
- "gitVersion"
- "goVersion"
- "platform"
condition: and
extractors:
- type: json
json:
- '.gitVersion'