google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

AI PRP: Arbitrary file read in voilà-dashboard #458

Open JamesFoxxx opened 2 months ago

JamesFoxxx commented 2 months ago

voilà-dashboard is an official application within the Jupyter ecosystem which is very popular. This CVE is published 4 days and is emergent. according to the CVE description: Any deployment of voilà dashboard allows local file inclusion. the exploit also is as simple as one simple GET request: curl localhost:8866/static/etc/passwd

Ref: https://jupyter.org/ https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg