CVE Vulnerabilities

CVE-2024-41942

Published: Aug 08, 2024 | Modified: Aug 12, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the admin:users scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that admin:users is already an extremely privileged scope only granted to trusted users. In effect, admin:users is equivalent to admin=True, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. groups permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.

Affected Software

Name Vendor Start Version End Version
Jupyterhub Jupyter * 4.1.6 (excluding)
Jupyterhub Jupyter 5.0.0 (including) 5.0.0 (including)
Jupyterhub Jupyter 5.0.0-beta1 (including) 5.0.0-beta1 (including)
Jupyterhub Jupyter 5.0.0-beta2 (including) 5.0.0-beta2 (including)

References