Логотип exploitDog
bind:CVE-2022-31027
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-31027

Количество 2

Количество 2

nvd логотип

CVE-2022-31027

больше 3 лет назад

OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the *email* field provided to us by CILogon has a *domain* that matches one of the domains listed in `allowed_idps`.If `allowed_idps` contains `berkeley.edu`, you might expect only users with valid current credentials provided by University of California, Berkeley to be able to access the JupyterHub. However, CILogonOAuthenticator does *not* verify which provider is used by the user to login, only the email address provided. So a user can login with a GitHub account that has email set to

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-r7v4-jwx9-wx43

больше 3 лет назад

Authorization Bypass Through User-Controlled Key when using CILogonOAuthenticator oauthenticator

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-31027

OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of CILogonOAuthenticator is documented to be a list of domains that indicate the institutions whose users are authorized to access this JupyterHub. This authorization is validated by ensuring that the *email* field provided to us by CILogon has a *domain* that matches one of the domains listed in `allowed_idps`.If `allowed_idps` contains `berkeley.edu`, you might expect only users with valid current credentials provided by University of California, Berkeley to be able to access the JupyterHub. However, CILogonOAuthenticator does *not* verify which provider is used by the user to login, only the email address provided. So a user can login with a GitHub account that has email set to

CVSS3: 4.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-r7v4-jwx9-wx43

Authorization Bypass Through User-Controlled Key when using CILogonOAuthenticator oauthenticator

CVSS3: 4.2
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу