{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-14T17:38:20.161","vulnerabilities":[{"cve":{"id":"CVE-2023-25574","sourceIdentifier":"security-advisories@github.com","published":"2025-02-25T15:15:16.227","lastModified":"2025-09-02T21:36:09.113","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available."},{"lang":"es","value":"`jupyterhub-ltiauthenticator` es un autenticador de JupyterHub para la interoperabilidad de herramientas de aprendizaje (LTI). LTI13Authenticator, que se introdujo en `jupyterhub-ltiauthenticator` 1.3.0, no validaba las firmas JWT. Se cree que esto permite que LTI13Authenticator autorice una solicitud falsificada. Solo los usuarios que han configurado una instalación de JupyterHub para usar la clase de autenticador `LTI13Authenticator` se ven afectados. La versión 1.4.0 de `jupyterhub-ltiauthenticator` elimina LTI13Authenticator para solucionar el problema. No hay workarounds conocidos disponibles."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H","baseScore":10.0,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jupyter:lti_jupyterhub_authenticator:1.3.0:*:*:*:*:*:*:*","matchCriteriaId":"972A882C-4130-4E8C-9B39-B83A2AF78F24"}]}]}],"references":[{"url":"https:\/\/github.com\/jupyterhub\/ltiauthenticator\/blob\/3feec2e81b9d3b0ad6b58ab4226af640833039f3\/ltiauthenticator\/lti13\/validator.py#L122-L164","source":"security-advisories@github.com","tags":["Product"]},{"url":"https:\/\/github.com\/jupyterhub\/ltiauthenticator\/blob\/main\/CHANGELOG.md#140---2023-03-01","source":"security-advisories@github.com","tags":["Release Notes"]},{"url":"https:\/\/github.com\/jupyterhub\/ltiauthenticator\/security\/advisories\/GHSA-mcgx-2gcr-p3hp","source":"security-advisories@github.com","tags":["Vendor Advisory"]}]}}]}