MEDIUM 4.5 PyPI
Cross-Site Request Forgery in JupyterHub
GHSA-7xx3-qp5w-fw96 · BIT-jupyterhub-2020-36191 · CVE-2020-36191 · PYSEC-2021-67
Published · Modified
Description
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-36191
- WEB https://github.com/jupyterhub/jupyterhub/issues/3304
- ADVISORY https://github.com/advisories/GHSA-7xx3-qp5w-fw96
- PACKAGE https://github.com/jupyterhub/jupyterhub
- WEB https://github.com/jupyterhub/jupyterhub/releases
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/jupyterhub/PYSEC-2021-67.yaml
Ready to move
Start Securing
Free, no credit card | First findings in minutes