google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

AI PRP: Jupyter Lab Exposed Ui RCE #459

Open JamesFoxxx opened 2 months ago

JamesFoxxx commented 2 months ago

it would be awesome if you let me start working on finding a way to discover Jupyter Lab exposed UIs (not Jupyter Notebook which is a classic product), I like to find a way to trigger an OOB at the first step.

maoning commented 2 months ago

Hi @JamesFoxxx ,

Thanks for your request! This vulnerability is in scope for the reward program. Please complete the following items:

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!