cbcvebase.
CVE-2024-41942
published 2024-08-08

CVE-2024-41942: JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the…

PriorityP343high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.59%
44.9th percentile
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianjupyterhub< jupyterhub 5.2.1+ds1-1 (forky)jupyterhub 5.2.1+ds1-1 (forky)
jupyterjupyterhub< 4.1.64.1.6
jupyterjupyterhub
jupyterhubjupyterhub< 4.1.64.1.6
jupyterhubjupyterhub< ff2db557a85b6980f90c3158634bf924063ab8baff2db557a85b6980f90c3158634bf924063ab8ba
jupyterhubjupyterhub
jupyterhubjupyterhub>= 0 < 5.2.1+ds1-15.2.1+ds1-1
jupyterhubjupyterhub>= 0 < 5.2.1+ds1-15.2.1+ds1-1
jupyterhubjupyterhub>= 0 < 4.1.64.1.6
jupyterhubjupyterhub>= 0 < 99e2720b0fc626cbeeca3c6337f917fdacfaa42899e2720b0fc626cbeeca3c6337f917fdacfaa428
jupyterhubjupyterhub>= 5.0.0 < 5.1.05.1.0

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.