CVE-2020-36191: Cross-Site Request Forgery in JupyterHub
(updated )
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf
field, as demonstrated by a /hub/api/user request (to add or remove a user account).
References
Detect and mitigate CVE-2020-36191 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →