PYSEC-2018-68

    Dashboard / Vulnerabilities / PYSEC-2018-68

    PYSEC-2018-68

    Published: 18 Feb 2018Last Modified: 22 Nov 2024

    Summary:

    Details: An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.)

    Affected packages

    Package

    Name: oauthenticator

    Purl: pkg:pypi/oauthenticator

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    0.6.0
    0.6.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High