jupyterhub is vulnerable to Privilege Escalation
27
Low Risk
The scope-enforcement decorator treats a filtered admin scope as sufficient whenever a request carries no explicit resource filter, deferring any filtering to the request handler. Endpoints that create users or groups do not apply that deferred filtering, so a user granted a filtered admin scope such as admin:users!group=... or admin:groups!group=... can create users or groups outside their permitted scope. Before the fix this lets a partially privileged admin act beyond its assigned resource filter. The fix makes post-filtering explicit and opt-in so only listing endpoints accept filtered access.
You are affected if you are using a version that falls within the vulnerable range and you grant filtered admin roles such as admin:users!group=... or admin:groups!group=....
jupyterhub is vulnerable to Privilege Escalation in versions 2.0.0 - 5.5.0.
Upgrade the jupyterhub library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant