Sensitive information sent insecurely In jupyterhub-systemdspawner
Description
user-readable api tokens in systemd units for JupyterHub
Impact
user API tokens issued to single-user servers are specified in the environment of systemd units, which are accessible to all users.
In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default.
Patches
Patched in jupyterhub-systemdspawner v0.15
Workarounds
No workaround other than upgrading systemdspawner to 0.15
For more information
If you have any questions or comments about this advisory:
Open a thread in the Jupyter forum
Email us at [email protected]
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 0.15.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.