oauthenticator
PyPI6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting oauthenticatorpage 1 of 1
- CVE-2018-7206HIGHCVSS 8.8✓ Fixed in 0.7.32018-02-18
vulnerable: 0.6.0, 0.6.1, 0.7.0, 0.7.1, 0.7.2
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing m…
- CVE-2020-26250MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.12.22020-12-01
vulnerable: 0.12.0, 0.12.1
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authen…
- CVE-2022-31027MEDIUMCVSS 4.2EG 4.2✓ Fixed in 15.0.02022-06-09
vulnerable: 0.1.0 ... 14.2.0 (28 versions)
OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub o…
- CVE-2024-29033HIGHCVSS 7.5EG 7.5✓ Fixed in 16.3.02024-03-20
vulnerable: 0.1.0 ... 16.2.1 (43 versions)
OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. `GoogleOAuthenticator.hosted_domain` is used to restrict what Google ac…
- CVE-2024-37300HIGHCVSS 8.1EG 8.1✓ Fixed in 16.3.12024-06-12
vulnerable: 0.1.0 ... 16.3.0 (44 versions)
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be configured to allow all users from a particular institution only.…
- CVE-2026-33175HIGHCVSS 8.8EG 8.8✓ Fixed in 17.4.02026-04-03
vulnerable: 0.1.0 ... 17.3.0 (49 versions)
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unverified email addre…
Check whether oauthenticator is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for oauthenticator CVEs against the assets you own.
Start Free Scan →