CVE-2020-36191
published 2021-01-13CVE-2020-36191: JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user…
PriorityP420medium4.5CVSS 3.1
AVNACLPRHUIRSUCNIHAN
EPSS
0.50%
40.3th percentile
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyterhub | < jupyterhub 3.0.0+ds1-1 (bookworm) | jupyterhub 3.0.0+ds1-1 (bookworm) |
| jupyter | jupyterhub | — | — |
| jupyterhub | jupyterhub | >= 0 < 3.0.0+ds1-1 | 3.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 3.0.0+ds1-1 | 3.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 3.0.0+ds1-1 | 3.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 1.2.0b1 | 1.2.0b1 |
CVSS provenance
nvdv3.14.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.5MEDIUM
vendor_debian4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-Site Request Forgery in JupyterHub
osv·2022-05-24
CVE-2020-36191 [MEDIUM] Cross-Site Request Forgery in JupyterHub
Cross-Site Request Forgery in JupyterHub
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an `_xsrf` field, as demonstrated by a /hub/api/user request (to add or remove a user account).
GHSA
Cross-Site Request Forgery in JupyterHub
ghsa·2022-05-24
CVE-2020-36191 [MEDIUM] CWE-352 Cross-Site Request Forgery in JupyterHub
Cross-Site Request Forgery in JupyterHub
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an `_xsrf` field, as demonstrated by a /hub/api/user request (to add or remove a user account).
OSV
CVE-2020-36191: JupyterHub 1
osv·2021-01-13·CVSS 4.5
CVE-2020-36191 [MEDIUM] CVE-2020-36191: JupyterHub 1
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
Debian
CVE-2020-36191: jupyterhub - JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsr...
vendor_debian·2020·CVSS 4.5
CVE-2020-36191 [MEDIUM] CVE-2020-36191: jupyterhub - JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsr...
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
Scope: local
bookworm: resolved (fixed in 3.0.0+ds1-1)
forky: resolved (fixed in 3.0.0+ds1-1)
sid: resolved (fixed in 3.0.0+ds1-1)
trixie: resolved (fixed in 3.0.0+ds1-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33709 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.5
CVE-2026-33709 [MEDIUM] CVE-2026-33709 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33709 :
JupyterHub vulnerability analysis and mitigation
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4.
Source : NVD
## 5.1
Score
Published April 3, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
JupyterHub
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPS
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
2021-01-13
Published