user API tokens issued to single-user servers are specified in the environment of systemd units, which are accessible to all users.
In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default.
Patched in jupyterhub-systemdspawner v0.15
No workaround other than upgrading systemdspawner to 0.15
If you have any questions or comments about this advisory: * Open a thread in the Jupyter forum * Email us at security@ipython.org
{
"cwe_ids": [
"CWE-668"
],
"nvd_published_at": null,
"github_reviewed_at": "2020-12-09T16:25:35Z",
"github_reviewed": true,
"severity": "HIGH"
}