Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
Vulnerability Description
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不充分特权处理不恰当
Vulnerability Title
JupyterHub 安全漏洞
Vulnerability Description
JupyterHub是JupyterHub开源的一款用于Jupyter的多用户服务器。 JupyterHub 存在安全漏洞,该漏洞源于被授予 admin:users 的用户可以通过使自己成为完全管理员用户来提升自己的权限。
CVSS Information
N/A
Vulnerability Type
N/A