Skip to content

AI PRP: D-tale Server exposed UI RCE #561

@VickyTheViking

Description

@VickyTheViking

According to the D-tale configuration: https://github.com/man-group/dtale/blob/master/docs/CONFIGURATION.md
We can disable authentication, and also have Python as the query engine, which opens the door for Python code injection.

To learn more, visit the detailed report page here: huntr.com bounty details.

Metadata

Metadata

Labels

Contributor mainThe main issue a contributor is working on (top of the contribution queue).PRP:Acceptedtemplated

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions