GHSA-mcgx-2gcr-p3hpCriticalCVSS 10.0

LTI JupyterHub Authenticator does not properly validate JWT Signature

Published
February 25, 2025
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Only users that has configured a JupyterHub installation to use the authenticator class LTI13Authenticator are influenced.

LTI13Authenticator that was introduced in jupyterhub-ltiauthenticator 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request granting access to existing and new user identities.

Patches

None.

Workarounds

None.

References

🎯 Affected products1

  • pip/jupyterhub-ltiauthenticator:= 1.3.0

🔗 References (6)