`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available.
References
Configurations
History
02 Sep 2025, 21:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Jupyter lti Jupyterhub Authenticator
Jupyter |
|
Summary |
|
|
References | () https://github.com/jupyterhub/ltiauthenticator/blob/3feec2e81b9d3b0ad6b58ab4226af640833039f3/ltiauthenticator/lti13/validator.py#L122-L164 - Product | |
References | () https://github.com/jupyterhub/ltiauthenticator/blob/main/CHANGELOG.md#140---2023-03-01 - Release Notes | |
References | () https://github.com/jupyterhub/ltiauthenticator/security/advisories/GHSA-mcgx-2gcr-p3hp - Vendor Advisory | |
CPE | cpe:2.3:a:jupyter:lti_jupyterhub_authenticator:1.3.0:*:*:*:*:*:*:* |
25 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-25 15:15
Updated : 2025-09-02 21:36
NVD link : CVE-2023-25574
Mitre link : CVE-2023-25574
CVE.ORG link : CVE-2023-25574
JSON object : View
Products Affected
jupyter
- lti_jupyterhub_authenticator
CWE
CWE-347
Improper Verification of Cryptographic Signature