CVE-2024-37300
Last modified
CVE-2024-37300 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only. This worked fine prior to JupyterHub 5.0, because `allow_all` did not take precedence over `identity_provider`. Since JupyterHub 5.0, `allow_all` does take precedence over `identity_provider`. On a hub with the same config, now all users will be allowed to login, regardless of `identity_provider`. `identity_provider` will basically be ignored. This is a documented change in JupyterHub 5.0, but is likely to catch many users by surprise. OAuthenticator 16.3.1 fixes the issue with JupyterHub 5.0, and does not affect previous versions. As a workaround, do not upgrade to JupyterHub 5.0 when using `GlobusOAuthenticator` in the prior configuration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-37300?
How severe is CVE-2024-37300?
How do I fix CVE-2024-37300?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-37295Aimeos is an Open Source e-commerce framework for online sho…7.2
- CVE-2024-37296The Aimeos HTML client provides Aimeos HTML components for e…5.3
- CVE-2024-37297WooCommerce is an open-source e-commerce platform built on W…5.4
- CVE-2024-37298gorilla/schema converts structs to and from form values. Pri…7.5
- CVE-2024-37299Discourse is an open source discussion platform. Prior to 3.…7.5
- CVE-2024-3730The Simple Membership plugin for WordPress is vulnerable to …5.4
- CVE-2024-37301Document Merge Service is a document template merge service …7.2
- CVE-2024-37302Synapse is an open-source Matrix homeserver. Synapse version…7.5
- CVE-2024-37303Synapse is an open-source Matrix homeserver. Synapse before …5.3
- CVE-2024-37304NuGet Gallery is a package repository that powers nuget.org.…6.1
- CVE-2024-37305oqs-provider is a provider for the OpenSSL 3 cryptography li…8.2
- CVE-2024-37306Computer Vision Annotation Tool (CVAT) is an interactive vid…7.1
Are you affected by CVE-2024-37300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
