Описание
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.12 (исключая)
cpe:2.3:a:jupyterhub:kubespawner:*:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00219
Низкий
6.8 Medium
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-863
CWE-863
Связанные уязвимости
CVSS3: 6.8
github
больше 5 лет назад
Possible pod name collisions in jupyterhub-kubespawner
EPSS
Процентиль: 44%
0.00219
Низкий
6.8 Medium
CVSS3
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-863
CWE-863