CVE-2020-15110

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/07/2020
Last modified:
18/11/2021

Description

In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jupyterhub:kubespawner:*:*:*:*:*:*:*:* 0.12 (excluding)