Improper Privilege Management Affecting jupyterhub package, versions [,4.1.6) [5.0.0b1,5.1.0)
Threat Intelligence
Exploit Maturity
Mature
EPSS
0.06% (30th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-JUPYTERHUB-7654158
- published 9 Aug 2024
- disclosed 8 Aug 2024
- credit Oliver Sanders
Introduced: 8 Aug 2024
CVE-2024-41942 Open this link in a new tabHow to fix?
Upgrade jupyterhub
to version 4.1.6, 5.1.0 or higher.
Overview
jupyterhub is a JupyterHub: A multi-user server for Jupyter notebooks
Affected versions of this package are vulnerable to Improper Privilege Management in apihandlers/users.py
. A high privileged user in the admin:users
scope (which is equivalent to admin=True
) can escalate to admin privileges by modifying their own grants.