CVE-2024-41942
published 2024-08-08CVE-2024-41942: JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the…
PriorityP343high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.59%
44.9th percentile
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users.
In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyterhub | < jupyterhub 5.2.1+ds1-1 (forky) | jupyterhub 5.2.1+ds1-1 (forky) |
| jupyter | jupyterhub | < 4.1.6 | 4.1.6 |
| jupyter | jupyterhub | — | — |
| jupyterhub | jupyterhub | < 4.1.6 | 4.1.6 |
| jupyterhub | jupyterhub | < ff2db557a85b6980f90c3158634bf924063ab8ba | ff2db557a85b6980f90c3158634bf924063ab8ba |
| jupyterhub | jupyterhub | — | — |
| jupyterhub | jupyterhub | >= 0 < 5.2.1+ds1-1 | 5.2.1+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 5.2.1+ds1-1 | 5.2.1+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 4.1.6 | 4.1.6 |
| jupyterhub | jupyterhub | >= 0 < 99e2720b0fc626cbeeca3c6337f917fdacfaa428 | 99e2720b0fc626cbeeca3c6337f917fdacfaa428 |
| jupyterhub | jupyterhub | >= 5.0.0 < 5.1.0 | 5.1.0 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
ghsa·2024-08-08
CVE-2024-41942 [HIGH] CWE-274 JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
### Summary
If a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user.
### Details
The `admin:users` scope allows a user to edit user records:
> admin:users
>
> Read, write, create and delete users and their authentication state, not including their servers or tokens.
>
> -- https://jupyterhub.readthedocs.io/en/stable/rbac/scopes.html#available-scopes
However, this includes making users admins. Admin users are granted scopes beyond `admin:users` making this a mechanism by which granted scopes may be escalated.
### Impact
The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted
OSV
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
osv·2024-08-08
CVE-2024-41942 [HIGH] JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
### Summary
If a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user.
### Details
The `admin:users` scope allows a user to edit user records:
> admin:users
>
> Read, write, create and delete users and their authentication state, not including their servers or tokens.
>
> -- https://jupyterhub.readthedocs.io/en/stable/rbac/scopes.html#available-scopes
However, this includes making users admins. Admin users are granted scopes beyond `admin:users` making this a mechanism by which granted scopes may be escalated.
### Impact
The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted
OSV
CVE-2024-41942: JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks
osv·2024-08-08
CVE-2024-41942 CVE-2024-41942: JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users.
In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.
OSV
CVE-2024-41942: JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks
osv·2024-08-08·CVSS 7.2
CVE-2024-41942 [HIGH] CVE-2024-41942: JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.
Debian
CVE-2024-41942: jupyterhub - JupyterHub is software that allows one to create a multi-user server for Jupyter...
vendor_debian·2024·CVSS 7.2
CVE-2024-41942 [HIGH] CVE-2024-41942: jupyterhub - JupyterHub is software that allows one to create a multi-user server for Jupyter...
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.
Scope: local
bookworm: ope
No detection rules found.
No public exploits indexed.
2024-08-08
Published