Логотип exploitDog
bind:CVE-2020-26261
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26261

Количество 2

Количество 2

nvd логотип

CVE-2020-26261

около 5 лет назад

jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default. This is patched in jupyterhub-systemdspawner v0.15

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-cg54-gpgr-4rm6

около 5 лет назад

user-readable api tokens in systemd units for JupyterHub

CVSS3: 7.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26261

jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default. This is patched in jupyterhub-systemdspawner v0.15

CVSS3: 7.9
0%
Низкий
около 5 лет назад
github логотип
GHSA-cg54-gpgr-4rm6

user-readable api tokens in systemd units for JupyterHub

CVSS3: 7.9
0%
Низкий
около 5 лет назад

Уязвимостей на страницу