Home » Database

AVID-2026-R1191

Description

JupyterHub’s LTI13Authenticator: JWT signature not validated (CVE-2023-25574)

Details

jupyterhub-ltiauthenticator is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in jupyterhub-ltiauthenticator 1.3.0 wasn’t validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class LTI13Authenticator are affected. jupyterhub-ltiauthenticator version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available.

Reason for inclusion in AVID: The CVE describes a critical vulnerability in jupyterhub-ltiauthenticator’s LTI13Authenticator, a component used in JupyterHub deployments to run AI/ML notebook environments. It concerns improper JWT signature verification, enabling forged requests with potential compromise of notebooks and data. This affects a software component in the AI software stack (dependencies/runtimes used to build/run general-purpose AI systems), is a security vulnerability, and the report provides explicit signal (CVE id, affected versions, remediation). Therefore it should be kept for AVID curation.

References

Affected or Relevant Artifacts

  • Developer: jupyterhub
  • Deployer: jupyterhub
  • Artifact Details:
TypeName
Systemltiauthenticator

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score10.0
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-347CWE-347: Improper Verification of Cryptographic Signature

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2025-02-25
  • Version: 0.3.3
  • AVID Entry