-
Notifications
You must be signed in to change notification settings - Fork 3.2k
Open
Labels
template-contributionNuclei template contributionNuclei template contribution
Description
Is there an existing template for this?
- I have searched the existing templates.
Nuclei Template
id: unauthenticated-argocd-service
info:
name: Unauthenticated Argo CD service
author: Thowbik Dustan
severity: critical
description: |
Detects if the ArgoCD service is exposed without authentication by checking argo CD endpoint and title.
metadata:
max-request: 2
tags: argocd, exposed-service, workflows, discovery
requests:
- method: GET
path:
- "{{BaseURL}}/workflows/default"
redirects: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- "<title>Argo CD</title>"
- "<title>ArgoCD</title>"
- "<title>Argo</title>"
- "<title>Argocd</title>"
- "<title>argocd</title>"
- type: status
status:
- 200Relevant dumped responses
Anything else?
This template finds any Argocd service which are unauthenticated and can be exploited by anyone.
Metadata
Metadata
Assignees
Labels
template-contributionNuclei template contributionNuclei template contribution