Patch for Restricting Google Account Authorization in OAuthenticator
CVE-2024-29033

7.5HIGH

Key Information:

Vendor

Jupyterhub

Vendor
CVE Published:
20 March 2024

What is CVE-2024-29033?

The OAuthenticator plugin for JupyterHub, which facilitates authentication via popular OAuth providers, has a significant vulnerability related to the GoogleOAuthenticator.hosted_domain setting. This feature is designed to restrict access to Google accounts linked with specific verified domains. However, before the release of version 16.3.0, the restriction mechanism was improperly configured, allowing any Google account ending with the specified domain to be authorized. Consequently, accounts could be created by anyone with previous access to an email associated with the domain, exposing JupyterHub instances to unauthorized access. Version 16.3.0 addresses this issue with a patch. In the interim, administrators are advised to use alternative access control methods such as allowed_users or allowed_google_groups to mitigate potential security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

oauthenticator < 16.3.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.