EXPOSURE Kubeflow
SEVERITY HIGH
PROBE GET :8080/api/workgroup/env-info
Is your Kubeflow exposed?
Dashboard without auth: pipelines, notebooks, and cluster ML workflows for anyone who reaches the URL.
Scan a host you own → Fix card
Why it matters
An open Kubeflow central dashboard exposes pipelines, notebooks, and cluster ML workflows to anyone who can reach the URL.
How common is it?
A published population estimate for Kubeflow is still collecting. See the census methodology.
Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.
Fix it
The full walkthrough lives on the fix card, kept current in one place: