ZeroHour

CVE-2020-15110

PoC
CVSS 3.1
8.1 high
EPSS
1%p64
Published
()
Modified
Description

In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.

Vendors
jupyterhub
Products
kubespawner
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.