Patch for Restricting Google Account Authorization in OAuthenticator
CVE-2024-29033
What is CVE-2024-29033?
The OAuthenticator plugin for JupyterHub, which facilitates authentication via popular OAuth providers, has a significant vulnerability related to the GoogleOAuthenticator.hosted_domain setting. This feature is designed to restrict access to Google accounts linked with specific verified domains. However, before the release of version 16.3.0, the restriction mechanism was improperly configured, allowing any Google account ending with the specified domain to be authorized. Consequently, accounts could be created by anyone with previous access to an email associated with the domain, exposing JupyterHub instances to unauthorized access. Version 16.3.0 addresses this issue with a patch. In the interim, administrators are advised to use alternative access control methods such as allowed_users or allowed_google_groups to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
oauthenticator < 16.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
