Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AI PRP: Jupyter Notebook Exposed Ui RCE #453

Open
JamesFoxxx opened this issue Apr 4, 2024 · 3 comments
Open

AI PRP: Jupyter Notebook Exposed Ui RCE #453

JamesFoxxx opened this issue Apr 4, 2024 · 3 comments
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Accepted

Comments

@JamesFoxxx
Copy link
Contributor

JamesFoxxx commented Apr 4, 2024

it would be awesome if you let me improve this plugin, instead of current response body checking, I want to check if it is possible to directly run code without many HTTP requests to check an exposed UI.

@maoning maoning added PRP:Accepted Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. labels Apr 18, 2024
@maoning
Copy link
Collaborator

maoning commented Apr 18, 2024

Hi @JamesFoxxx ,

Thanks for your request! This vulnerability is in scope for the reward program.

Could you make sure the RCE payload works with most versions of jupyter notebook? I have seen false negative in the current plugin in the past due to version differences.

Please keep in mind that the Tsunami Scanner Team will only be able to work at one issue at a time for each participant so please hold on the implementation work for any other requests you might have.

Thanks!

@JamesFoxxx
Copy link
Contributor Author

@maoning I'm not familiar with writing web fingerprints because my knowledge in bash scripting is not enough and it can take a lot of my time to write a script in bash. if you give me a separate bounty for the web fingerprint I can ask my friend to write this part. ( I'll work with my friend internally so no need to any changes for you and I'll give the 500$ bounty to my friend after I receive the total bounty)
please let me know.

@maoning
Copy link
Collaborator

maoning commented May 15, 2024

@JamesFoxxx sounds good, you can separate the fingerprint portion out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Accepted
Projects
None yet
Development

No branches or pull requests

2 participants