-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the jwt_verify_and_decode method in validator.py explicitly disabling JWT signature verification via jwt.decode(..., verify=False). The CWE-347 description and advisory references confirm this lack of validation allows forged requests. The code segment provided in the vulnerability details (lines 122-164) corresponds to this function's implementation. The removal of LTI13Authenticator in v1.4.0 further corroborates this was the root cause.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| jupyterhub-ltiauthenticator | pip | = 1.3.0 | 1.4.0 |
Ongoing coverage of React2Shell