`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Feb 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available. | |
Title | JupyterHub's LTI13Authenticator: JWT signature not validated | |
Weaknesses | CWE-347 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T14:51:02.754Z
Reserved: 2023-02-07T17:10:00.741Z
Link: CVE-2023-25574

Updated: 2025-02-25T14:50:49.587Z

Status : Received
Published: 2025-02-25T15:15:16.227
Modified: 2025-02-25T15:15:16.227
Link: CVE-2023-25574

No data.