Possible pod name collisions in jupyterhub-kubespawner
CVE-2020-15110

6.8MEDIUM

Key Information:

Vendor

Jupyterhub

Vendor
CVE Published:
17 July 2020

What is CVE-2020-15110?

In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.

Affected Version(s)

kubespawner < 0.12

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.