PT-2021-23211 · Unknown · Jupyterhub+1

Fritterhoff

·

Published

2021-11-04

·

Updated

2024-03-06

·

CVE-2021-41247

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions JupyterHub versions prior to 1.5
Description The issue affects users of JupyterLab with JupyterHub who have multiple JupyterLab tabs open in the same browser session. When logging out, fresh credentials for the single-user server are reinstated if another active JupyterLab session is open, resulting in incomplete logout.
Recommendations For versions prior to 1.5, upgrade to JupyterHub 1.5. For distributed deployments, patch jupyterhub in the user environment. As a temporary workaround, ensure that only one JupyterLab tab is open when logging out.

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BIT-JUPYTERHUB-2021-41247
CVE-2021-41247
GHSA-CW7P-Q79F-M2V7
PYSEC-2021-386

Affected Products

Jupyterhub
Jupyterlab