- Description
- `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available.
- Source
- security-advisories@github.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-347
- Hype score
- Not currently trending
🚨 CVE-2023-25574 ⚠️🔴 CRITICAL (10) 🏢 jupyterhub - ltiauthenticator 🏗️ = 1.3.0 🔗 https://t.co/lBPiXr9i8z 🔗 https://t.co/gzXSDghHEm 🔗 https://t.co/tZTyBQYw6r #CyberCron #VulnAlert https://t.co/RzyuiJVcrW
@cybercronai
27 Feb 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerability Alert: LTI13Authenticator JWT Signature Not Validated 📅 Timeline: • Disclosure: 2023-03-01 • Patch Release: 2023-03-01 • Official Advisory Published: 2025-02-25 📌 Attribution: • Reported by GitHub, Inc. 🆔 CVE ID: CVE-2023-25574 📊 Base… https:/
@syedaquib77
25 Feb 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2023-25574: CRITICAL] Update to `jupyterhub-ltiauthenticator` version 1.4.0 immediately. A security vulnerability in LTI13Authenticator could authorize forged requests, affecting users of JupyterHub using th...#cybersecurity,#vulnerability https://t.co/HQI27ecvn4 https://t.c
@CveFindCom
25 Feb 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2023-25574 `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthen… https://t.co/cz3NTDACj7
@CVEnew
25 Feb 2025
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes