-
Notifications
You must be signed in to change notification settings - Fork 180
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AI PRP: Request Kubeflow Exposed UI #421
Comments
@maoning Hi, I read about this but I think it needs a lot more coding than a regular plugin, if you count this as a critical rating with top bounty I'm ready to implement a plugin for this as fast as possible! |
Hi @am0o0, since you already picked up another request, let's put this on hold for now unless you want to work on this first. If you could provide detailed vulnerability research, vulnerable service configurations and plugin implementation, then we will pay out the max bounty. |
Hello @maoning, it looks like you're the one responsible for assigning the bug hunters. I'm really excited to dive into this issue and create a plugin. Since it's my first time making one, could you please assign it to me? I'd appreciate it a lot! |
I'm pinging @tooryx too, maybe I receive a response faster. |
Hi @grandsilva, You can start working on this request and please complete the following tasks:
|
@maoning Unfortunately, setting up a Kubeflow central dashboard without authentication or misconfigured authorization is beyond my current abilities. I need to learn more about Kubernetes and Kustomize first. For now, there is a production-ready setup according to their manifest: I’ve begun to dive deeper into Kubernetes and how to use Kustomize to create a vulnerable configuration. |
I opened an issue for better tracking: |
References:
https://www.microsoft.com/en-us/security/blog/2020/06/10/misconfigured-kubeflow-workloads-are-a-security-risk/?spm=a2c4g.11174386.n2.3.5c871051EQNQto
https://www.zdnet.com/article/microsoft-discovers-cryptomining-gang-hijacking-ml-focused-kubernetes-clusters/
More vulnerability research is needed to find out how RCE can be verified in Kubeflow.
Please read the rules of engagement first at #409.
The text was updated successfully, but these errors were encountered: