jupyterhub@4.1.3 vulnerabilities

JupyterHub: A multi-user server for Jupyter notebooks

Direct Vulnerabilities

Known vulnerabilities in the jupyterhub package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Improper Privilege Management

jupyterhub is a JupyterHub: A multi-user server for Jupyter notebooks

Affected versions of this package are vulnerable to Improper Privilege Management in apihandlers/users.py. A high privileged user in the admin:users scope (which is equivalent to admin=True) can escalate to admin privileges by modifying their own grants.

How to fix Improper Privilege Management?

Upgrade jupyterhub to version 4.1.6, 5.1.0 or higher.

[,4.1.6) [5.0.0b1,5.1.0)