7.9
CVSSv3

CVE-2020-26261

Published: 09/12/2020 Updated: 10/12/2020
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.9 | Impact Score: 5.8 | Exploitability Score: 1.5
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default. This is patched in jupyterhub-systemdspawner v0.15

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jupyterhub systemdspawner