VDB
Sign up
—

PYSEC-2021-384

Quick fix

PYSEC-2021-384 — jupyterhub-firstuseauthenticator: upgrade to the fixed version with the command below.

pip install --upgrade 'jupyterhub-firstuseauthenticator>=1.0.0'

Details

FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is known or guessed. One may upgrade to version 1.0.0 or apply a patch manually to mitigate the vulnerability. For those who cannot upgrade, there is no complete workaround, but a partial mitigation exists. One can disable user creation with `c.FirstUseAuthenticator.create_users = False`, which will only allow login with fully normalized usernames for already existing users prior to jupyterhub-firstuserauthenticator 1.0.0. If any users have never logged in with their normalized username (i.e. lowercase), they will still be vulnerable until a patch or upgrade occurs.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/jupyterhub-firstuseauthenticator
Introduced in: 0Fixed in: 1.0.0
Fixpip install --upgrade 'jupyterhub-firstuseauthenticator>=1.0.0'

References