CVE-2018-7206

HIGHCVSS 8.8/10EPSS 1.80%

Last modified

CVE-2018-7206 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. EPSS estimates a 1.80% chance of exploitation in the next 30 days.

Description

An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.)

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.80%

75.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
JupyterOauthenticator0.6.0
JupyterOauthenticator0.6.1
JupyterOauthenticator0.7.0
JupyterOauthenticator0.7.1
JupyterOauthenticator0.7.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-7206?
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were not allowed to access other users' accounts, but could create their own accounts on the Hub linked to their GitLab account. GitLab authentication not using gitlab_group_whitelist is unaffected. No other Authenticators are affected.)
How severe is CVE-2018-7206?
CVE-2018-7206 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.80% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7206?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-7206?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST