VDB

CVE-2024-41942

CVE-2024-41942 PUBLISHED CVSS 7.199999809265137 HIGH

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.

EPSS 0.59% · 46.4th percentile

Risk Scores

CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.59%
46.4th percentile

Affected Products

VendorProductVersions
Bitnamijupyterhub0, 5.0.0
Bitnamijupyterhub0, 5.0.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Aug 8, 2024 CVE Published
  • Aug 8, 2024 PoC Published
  • Aug 13, 2024 EPSS Score
  • Sep 3, 2024 EPSS Score
  • Sep 24, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 16, 2024 EPSS Score
  • Nov 6, 2024 EPSS Score
  • Nov 27, 2024 EPSS Score
  • Dec 19, 2024 EPSS Score
  • Jan 9, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›