CVE-2023-25574 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-lti…
Critical CVSS: 10.0

CVE-2023-25574

`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available.
Vendor
Jupyter
Product
Lti Jupyterhub Authenticator
CWE
CWE-347
Yayın Tarihi
2025-02-25 15:15:16
Güncelleme
2025-09-02 21:36:09
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar