JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf
field, as demonstrated by a /hub/api/user request (to add or remove a user account).
{ "nvd_published_at": "2021-01-13T04:15:00Z", "cwe_ids": [ "CWE-352" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-06-23T18:03:58Z" }