JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
References
Link | Resource |
---|---|
https://github.com/jupyterhub/jupyterhub/releases | Third Party Advisory |
https://github.com/jupyterhub/jupyterhub/issues/3304 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-01-12 20:15
Updated : 2021-01-19 11:58
NVD link : CVE-2020-36191
Mitre link : CVE-2020-36191
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
jupyter
- jupyterhub