Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: zenml-io/zenml weak credentials #444

Open
secureness opened this issue Mar 31, 2024 · 4 comments
Open

AI PRP: zenml-io/zenml weak credentials #444

secureness opened this issue Mar 31, 2024 · 4 comments
Assignees
Labels
ai-bounty-prp Identify an AI bounty plugin Contributor main The main issue a contributor is working on (top of the contribution queue).

Comments

@secureness
Copy link
Contributor

zenml is a well-known open-source project for production-ready MLOps pipelines.

it contains a dashboard which contains default credentials ( default/emptyPass ).

@maoning maoning added Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. ai-bounty-prp Identify an AI bounty plugin labels Apr 2, 2024
@maoning
Copy link
Collaborator

maoning commented Apr 2, 2024

@secureness Thanks for the report, I'm putting it in the queue for now. Let's prioritize on getting the active one you are working on merged first. Then you can pick up this one.

@tooryx tooryx added Contributor main The main issue a contributor is working on (top of the contribution queue). and removed Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. labels May 22, 2024
@tooryx
Copy link
Member

tooryx commented May 22, 2024

Hi @secureness ,

Thanks for your request! This vulnerability is in scope for the reward program. Please submit our participation form and you can start working on the development.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!

@maoning
Copy link
Collaborator

maoning commented May 22, 2024

@secureness If weak credential testing requires custom fingerprinting against the web service, please add the fingerprinting logic similar to

. This would ensure that the service is correctly identified & labelled in the vulnerability reporting.

@secureness
Copy link
Contributor Author

PR: #491
testbeds: google/security-testbeds#57

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ai-bounty-prp Identify an AI bounty plugin Contributor main The main issue a contributor is working on (top of the contribution queue).
Projects
None yet
Development

No branches or pull requests

3 participants