Impact
Only users that has configured a JupyterHub installation to use the authenticator class LTI13Authenticator are influenced.
LTI13Authenticator that was introduced in jupyterhub-ltiauthenticator 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.
Patches
None.
Workarounds
None.
References
Impact
Only users that has configured a JupyterHub installation to use the authenticator class
LTI13Authenticatorare influenced.LTI13Authenticator that was introduced in
jupyterhub-ltiauthenticator1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.Patches
None.
Workarounds
None.
References