Vulnerability Description
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jupyter | Jupyterhub | 1.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/jupyterhub/jupyterhub/issues/3304ExploitThird Party Advisory
- https://github.com/jupyterhub/jupyterhub/releasesThird Party Advisory
- https://github.com/jupyterhub/jupyterhub/issues/3304ExploitThird Party Advisory
- https://github.com/jupyterhub/jupyterhub/releasesThird Party Advisory
FAQ
What is CVE-2020-36191?
CVE-2020-36191 is a vulnerability with a CVSS score of 4.5 (MEDIUM). JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
How severe is CVE-2020-36191?
CVE-2020-36191 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36191?
Check the references section above for vendor advisories and patch information. Affected products include: Jupyter Jupyterhub.