Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-48311

Опубликовано: 08 дек. 2023
Источник: nvd
CVSS3: 8
CVSS3: 4.3
EPSS Низкий

Описание

dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers. Users of JupyterHub deployments running DockerSpawner starting with 0.11.0 without specifying DockerSpawner.allowed_images configuration allow users to launch any pullable docker image, instead of restricting to only the single configured image, as intended. This issue has been addressed in commit 3ba4b665b which has been included in dockerspawner release version 13. Users are advised to upgrade. Users unable to upgrade should explicitly set DockerSpawner.allowed_images to a non-empty list containing only the default image will result in the intended default behavior.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jupyter:dockerspawner:*:*:*:*:*:*:*:*
Версия от 0.11.0 (включая) до 13.0 (исключая)

EPSS

Процентиль: 48%
0.00246
Низкий

8 High

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

DockerSpawner allows any image by default

EPSS

Процентиль: 48%
0.00246
Низкий

8 High

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-20
NVD-CWE-noinfo