binderhub
Turn a Git repo into a collection of interactive notebooks
Activity
- Latest release
- 7y ago
- Total releases
- 1
- Cadence
- —
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Nov 07, 2018
| Version | Released | |
|---|---|---|
0.1.0
initial
1 CVE
CVE-2021-39159
GHSA-9jjr-qqfp-ppwx
PYSEC-2021-371
Aug 30, 2021
remote code execution via git repo provider
Critical
Network
Low
None
ImpactA remote code execution vulnerability has been identified in BinderHub, where providing BinderHub with maliciously crafted input could execute code in the BinderHub context, with the potential to egress credentials of the BinderHub deployment, including JupyterHub API tokens, kubernetes service accounts, and docker registry credentials. This may provide the ability to manipulate images and other user created pods in the deployment, with the potential to escalate to the host depending on the underlying kubernetes configuration. PatchesPatch below, or on GitHub
WorkaroundsDisable the git repo provider by specifying the
ReferencesCredit: Jose Carlos Luna Duran (CERN) and Riccardo Castellotti (CERN). For more informationIf you have any questions or comments about this advisory:
Affected versions
0.1.0
Fixed in
0.2.0
References
Updated Jul 08, 2026 · Source: OSV.dev |