Логотип exploitDog
bind:CVE-2023-48311
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48311

Количество 2

Количество 2

nvd логотип

CVE-2023-48311

около 2 лет назад

dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers. Users of JupyterHub deployments running DockerSpawner starting with 0.11.0 without specifying `DockerSpawner.allowed_images` configuration allow users to launch _any_ pullable docker image, instead of restricting to only the single configured image, as intended. This issue has been addressed in commit `3ba4b665b` which has been included in dockerspawner release version 13. Users are advised to upgrade. Users unable to upgrade should explicitly set `DockerSpawner.allowed_images` to a non-empty list containing only the default image will result in the intended default behavior.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-hfgr-h3vc-p6c2

около 2 лет назад

DockerSpawner allows any image by default

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48311

dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers. Users of JupyterHub deployments running DockerSpawner starting with 0.11.0 without specifying `DockerSpawner.allowed_images` configuration allow users to launch _any_ pullable docker image, instead of restricting to only the single configured image, as intended. This issue has been addressed in commit `3ba4b665b` which has been included in dockerspawner release version 13. Users are advised to upgrade. Users unable to upgrade should explicitly set `DockerSpawner.allowed_images` to a non-empty list containing only the default image will result in the intended default behavior.

CVSS3: 8
0%
Низкий
около 2 лет назад
github логотип
GHSA-hfgr-h3vc-p6c2

DockerSpawner allows any image by default

CVSS3: 4.3
0%
Низкий
около 2 лет назад

Уязвимостей на страницу