Impact
Only users that has configured a JupyterHub installation to use the authenticator class LTI13Authenticator
are influenced.
LTI13Authenticator that was introduced in jupyterhub-ltiauthenticator
1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.
Patches
None.
Workarounds
None.
References
Impact
Only users that has configured a JupyterHub installation to use the authenticator class
LTI13Authenticator
are influenced.LTI13Authenticator that was introduced in
jupyterhub-ltiauthenticator
1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.Patches
None.
Workarounds
None.
References