Описание
jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default. This is patched in jupyterhub-systemdspawner v0.15
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ProductThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.15 (исключая)
cpe:2.3:a:jupyterhub:systemdspawner:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00162
Низкий
7.9 High
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-668
CWE-668
Связанные уязвимости
CVSS3: 7.9
github
около 5 лет назад
user-readable api tokens in systemd units for JupyterHub
EPSS
Процентиль: 38%
0.00162
Низкий
7.9 High
CVSS3
3.3 Low
CVSS2
Дефекты
CWE-668
CWE-668