google / tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
Apache License 2.0
860 stars 178 forks source link

AI PRP: Weak credential tester for kubeflow #512

Open grandsilva opened 1 week ago

grandsilva commented 1 week ago

Kubeflow official setup has a default credential: https://github.com/kubeflow/manifests?tab=readme-ov-file#port-forward

I can write a plugin to detect this with a successful login message, furthermore, I can check the weak credentials with out of band check by utilizing SSRF or code execution which I suggest SSRF.