3.5
CVSSv2

CVE-2020-36191

Published: 13/01/2021 Updated: 19/01/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.5 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jupyter jupyterhub 1.1.0

Vendor Advisories

Debian Bug report logs - #1014774 jupyterhub: CVE-2020-36191 Package: src:jupyterhub; Maintainer for src:jupyterhub is Debian Python Team <team+python@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Mon, 11 Jul 2022 19:15:01 UTC Severity: normal Tags: security, upstream Forwarded to ht ...