Loading
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
Use CWE-352, Jupyter vendor hub and Jupyterhub product page to widen CVE-2020-36191 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-28233, CVE-2024-41942 and CVE-2019-10255 for nearby disclosures in the same product family.