LTI JupyterHub Authenticator does not properly validate JWT Signature
Critical severity
GitHub Reviewed
Published
Feb 25, 2025
in
jupyterhub/ltiauthenticator
•
Updated Feb 25, 2025
Description
Published by the National Vulnerability Database
Feb 25, 2025
Published to the GitHub Advisory Database
Feb 25, 2025
Reviewed
Feb 25, 2025
Last updated
Feb 25, 2025
Impact
Only users that has configured a JupyterHub installation to use the authenticator class
LTI13Authenticator
are influenced.LTI13Authenticator that was introduced in
jupyterhub-ltiauthenticator
1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.Patches
None.
Workarounds
None.
References
References