id: apache-storm-unauth info: name: Apache Storm Unauth author: pikpikcu severity: medium description: Apache Storm instance is exposed. reference: - https://storm.apache.org/releases/current/STORM-UI-REST-API.html metadata: max-request: 1 tags: apache,unauth,misconfig http: - method: GET path: - '{{BaseURL}}/api/v1/cluster/summary' matchers-condition: and matchers: - type: word part: body words: - '"totalMem":' - '"stormVersion":' condition: and - type: status status: - 200 # digest: 4b0a00483046022100ed245a9215c88b9677f17bb48554383cb11b34574756ad01d17974c5423fea30022100a6bbf22b04245a524a07c899fdb4510372c3bbd3447950824e022de57640e7a6:922c64590222798bb761d5b6d8e72950