PYSEC-2020-52

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/jupyterhub-systemdspawner/PYSEC-2020-52.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2020-52
Aliases
Published
2020-12-09T17:15:00Z
Modified
2023-11-01T04:52:44.579829Z
Summary
[none]
Details

jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default. This is patched in jupyterhub-systemdspawner v0.15

References

Affected packages

PyPI / jupyterhub-systemdspawner

Package

Name
jupyterhub-systemdspawner
View open source insights on deps.dev
Purl
pkg:pypi/jupyterhub-systemdspawner

Affected ranges

Type
GIT
Repo
https://github.com/jupyterhub/systemdspawner
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.0

Affected versions

0.*

0.9
0.9.1
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
0.9.10
0.9.11
0.9.12
0.10
0.11
0.12
0.13
0.14