Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: Request Kubeflow Exposed UI #421

Open
maoning opened this issue Mar 18, 2024 · 9 comments
Open

AI PRP: Request Kubeflow Exposed UI #421

maoning opened this issue Mar 18, 2024 · 9 comments
Assignees
Labels
ai-bounty-prp Identify an AI bounty plugin Contributor main The main issue a contributor is working on (top of the contribution queue). PRP:Accepted

Comments

@maoning
Copy link
Collaborator

maoning commented Mar 18, 2024

References:

More vulnerability research is needed to find out how RCE can be verified in Kubeflow.

Please read the rules of engagement first at #409.

@maoning maoning added help wanted Extra attention is needed ai-bounty-prp Identify an AI bounty plugin labels Mar 18, 2024
@am0o0
Copy link
Contributor

am0o0 commented Mar 20, 2024

@maoning Hi, I read about this but I think it needs a lot more coding than a regular plugin, if you count this as a critical rating with top bounty I'm ready to implement a plugin for this as fast as possible!

@maoning
Copy link
Collaborator Author

maoning commented Mar 21, 2024

Hi @am0o0, since you already picked up another request, let's put this on hold for now unless you want to work on this first. If you could provide detailed vulnerability research, vulnerable service configurations and plugin implementation, then we will pay out the max bounty.

@grandsilva
Copy link
Contributor

Hello @maoning, it looks like you're the one responsible for assigning the bug hunters.

I'm really excited to dive into this issue and create a plugin. Since it's my first time making one, could you please assign it to me? I'd appreciate it a lot!

@grandsilva
Copy link
Contributor

Hi,
It's been two weeks since my initial comment and there hasn't been a response. Should I create a new issue to address the matter, or is there another course of action you would recommend? I'm concerned that my previous comment might have been overlooked. @tooryx @maoning

@grandsilva
Copy link
Contributor

I'm pinging @tooryx too, maybe I receive a response faster.

@maoning maoning assigned maoning and grandsilva and unassigned maoning Jun 11, 2024
@maoning
Copy link
Collaborator Author

maoning commented Jun 11, 2024

Hi @grandsilva,

You can start working on this request and please complete the following tasks:

@maoning maoning added PRP:Accepted Contributor main The main issue a contributor is working on (top of the contribution queue). and removed help wanted Extra attention is needed labels Jun 11, 2024
@grandsilva
Copy link
Contributor

@maoning Unfortunately, setting up a Kubeflow central dashboard without authentication or misconfigured authorization is beyond my current abilities. I need to learn more about Kubernetes and Kustomize first.

For now, there is a production-ready setup according to their manifest:
https://github.com/kubeflow/manifests?tab=readme-ov-file#port-forward
This setup includes a default username and password, which administrators should change manually. However, they might forget to update these credentials after the launch. I can create a weak credential tester for it.

I’ve begun to dive deeper into Kubernetes and how to use Kustomize to create a vulnerable configuration.
Please add this PRP to my queue. Also, I’d like to create a new AI PRP for a weak credential tester.

@grandsilva
Copy link
Contributor

@tooryx @maoning Can I get an answer sooner? It's been a long time since the initial request already.

@grandsilva
Copy link
Contributor

@maoning Unfortunately, setting up a Kubeflow central dashboard without authentication or misconfigured authorization is beyond my current abilities. I need to learn more about Kubernetes and Kustomize first.

For now, there is a production-ready setup according to their manifest: https://github.com/kubeflow/manifests?tab=readme-ov-file#port-forward This setup includes a default username and password, which administrators should change manually. However, they might forget to update these credentials after the launch. I can create a weak credential tester for it.

I’ve begun to dive deeper into Kubernetes and how to use Kustomize to create a vulnerable configuration. Please add this PRP to my queue. Also, I’d like to create a new AI PRP for a weak credential tester.

I opened an issue for better tracking:
#512

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ai-bounty-prp Identify an AI bounty plugin Contributor main The main issue a contributor is working on (top of the contribution queue). PRP:Accepted
Projects
None yet
Development

No branches or pull requests

3 participants