QID 980206

QID 980206: Python (pip) Security Update for jupyterhub (GHSA-cw7p-q79f-m2v7)

Security update has been released for jupyterhub to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Users of JupyterLab with JupyterHub who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment.Workaround:
    The only workaround is to make sure that only one JupyterLab tab is open when you log out.
    Vendor References

    CVEs related to QID 980206

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cw7p-q79f-m2v7 jupyterhub URL Logo github.com/advisories/GHSA-cw7p-q79f-m2v7