CVE-2020-36191: Cross-Site Request Forgery (CSRF)
(updated )
JupyterHub allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user
request (to add or remove a user account).
References
Detect and mitigate CVE-2020-36191 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →