user-readable api tokens in systemd units for JupyterHub
High severity
GitHub Reviewed
Published
Dec 7, 2020
in
jupyterhub/systemdspawner
•
Updated Sep 27, 2024
Description
Reviewed
Dec 9, 2020
Published to the GitHub Advisory Database
Dec 9, 2020
Last updated
Sep 27, 2024
Impact
user API tokens issued to single-user servers are specified in the environment of systemd units, which are accessible to all users.
In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default.
Patches
Patched in jupyterhub-systemdspawner v0.15
Workarounds
No workaround other than upgrading systemdspawner to 0.15
For more information
If you have any questions or comments about this advisory:
References