CVE-2020-36191Cross-Site Request Forgery in Jupyterhub

Severity
4.5MEDIUMNVD
EPSS
0.1%
top 68.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateJun 30

Description

JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages3 packages

PyPIjupyterhub/jupyterhub< 1.2.0b1
Debianjupyterhub/jupyterhub< 3.0.0+ds1-1+2

🔴Vulnerability Details

4
OSV
Cross-Site Request Forgery in JupyterHub2022-05-24
GHSA
Cross-Site Request Forgery in JupyterHub2022-05-24
CVEList
CVE-2020-36191: JupyterHub 12021-01-13
OSV
CVE-2020-36191: JupyterHub 12021-01-13

📋Vendor Advisories

1
Debian
CVE-2020-36191: jupyterhub - JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsr...2020

🕵️Threat Intelligence

1
Wiz
CVE-2026-33709 Impact, Exploitability, and Mitigation Steps | Wiz

📄Research Papers

1
arXiv
Threat Assessment in Machine Learning based Systems2022-06-30
CVE-2020-36191 — Cross-Site Request Forgery | cvebase