GHSA-8x3m-m3x9-54fj

    Dashboard / Vulnerabilities / GHSA-8x3m-m3x9-54fj

    GHSA-8x3m-m3x9-54fj

    Published: 13 May 2022Last Modified: 3 Dec 2024

    Summary: JupyterHub OAuthenticator elevation of privilege

    Details: An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.)

    Affected packages

    Package

    Name: oauthenticator

    Purl: pkg:pypi/oauthenticator

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.6
    Fixed -0.6.2

    Affected versions

    0.6.0
    0.6.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High