CVE-2020-36191
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/u
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
MEDIUM · CVSS 4.5
EPSS 0.00124
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0