JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
2021-01-13T04:15:13.073
2024-11-21T05:28:58.730
Modified
CVSSv3.1: 4.5 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jupyter | jupyterhub | 1.1.0 | Yes |