Only users that has configured a JupyterHub installation to use the authenticator class LTI13Authenticator are influenced.
LTI13Authenticator that was introduced in jupyterhub-ltiauthenticator 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.
None.
None.
{
"github_reviewed": true,
"severity": "CRITICAL",
"nvd_published_at": "2025-02-25T15:15:16Z",
"cwe_ids": [
"CWE-347"
],
"github_reviewed_at": "2025-02-25T17:48:34Z"
}