user API tokens issued to single-user servers are specified in the environment of systemd units, which are accessible to all users.
In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default.
Patched in jupyterhub-systemdspawner v0.15
No workaround other than upgrading systemdspawner to 0.15
If you have any questions or comments about this advisory: * Open a thread in the Jupyter forum * Email us at security@ipython.org
{ "nvd_published_at": null, "cwe_ids": [ "CWE-668" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-12-09T16:25:35Z" }