Skip to content
JupyterGHSA-9x4q-3gxw-849f

JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

High7.2CVE-2024-41942 · Published Aug 8, 2024 · updated Sep 10, 2026

### Summary If a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. ### Details The `admin:users` scope allows a user to edit user records: > admin:users > > Read, write, create and delete users and their authentication state, not including their servers or tokens. > > -- https://jupyterhub.readthedocs.io/en/stable/rbac/scopes.html#available-scopes However, this includes making users admins. Admin users are granted scopes beyond `admin:users` making this a mechanism by which granted scopes may be escalated. ### Impact The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional.

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyterhub
PyPI
< 4.1.64.1.6
>= 5.0.0, < 5.1.05.1.0
Details and references

More Jupyter advisories

All Jupyter
Advisory
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
High7.6Aug 29, 2024
JupyterLab extension template is a `copier` template for JupyterLab extensions
Critical9.8Jul 16, 2024
Jupyter server on Windows discloses Windows user password hash
High7.5Jun 6, 2024
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
High8.1Mar 28, 2024
JupyterLab vulnerable to potential authentication and CSRF tokens leak
High7.6Jan 19, 2024
JupyterLab vulnerable to SXSS in Markdown Preview
Medium6.5Jan 19, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.