Impact
JupyterHub through 6.0.1 has a flaw permitting an authenticated user to register a hyphenated username that collides with an existing user's named‑server OAuth client ID, allowing the attacker to overwrite that client. This results in the targeted user's OAuth login failing and any existing tokens being revoked when the attacker stops the server. The weakness corresponds to CWE‑694, which involves improper handling of identifiers.
Affected Systems
All releases of JupyterHub up to and including version 6.0.1 are vulnerable. The flaw is present in the default OAuth implementation and applies to any deployment allowing user‑supplied named‑server identifiers.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity overall and the EPSS score is not available, implying no data on exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires authenticated access to a JupyterHub instance and cannot be exploited remotely over the network. The overall risk is low, but the potential to disrupt authentication for affected users warrants prompt remediation.
OpenCVE Enrichment