CyberRota Analysis
AI-GeneratedJupyterHub versions prior to 5.5.0 are vulnerable to a flaw in form-based login authenticators that allows an attacker to inject an unbounded username into failed-login logs. This can lead to resource exhaustion by consuming logging and storage capabilities, potentially impacting system performance. Organizations using JupyterHub should prioritize upgrading to version 5.5.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place an unbounded attacker-controlled username in failed-login logs, allowing an unauthenticated attacker to consume logging and storage resources. This issue is fixed in version 5.5.0.