{"id":"PYSEC-2025-120","details":"`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authenticator to authorize a forged request. Only users that has configured a JupyterHub installation to use the authenticator class `LTI13Authenticator` are affected. `jupyterhub-ltiauthenticator` version 1.4.0 removes LTI13Authenticator to address the issue. No known workarounds are available.","aliases":["CVE-2023-25574","GHSA-mcgx-2gcr-p3hp"],"modified":"2026-05-21T15:00:14.269578987Z","published":"2025-02-25T15:15:16.227Z","references":[{"type":"WEB","url":"https://github.com/jupyterhub/ltiauthenticator/blob/3feec2e81b9d3b0ad6b58ab4226af640833039f3/ltiauthenticator/lti13/validator.py#L122-L164"},{"type":"ADVISORY","url":"https://github.com/jupyterhub/ltiauthenticator/blob/main/CHANGELOG.md#140---2023-03-01"},{"type":"ADVISORY","url":"https://github.com/jupyterhub/ltiauthenticator/security/advisories/GHSA-mcgx-2gcr-p3hp"}],"affected":[{"package":{"name":"jupyterhub-ltiauthenticator","ecosystem":"PyPI","purl":"pkg:pypi/jupyterhub-ltiauthenticator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.3.0"}]}],"versions":["0.1","0.2","0.3","0.4.0","1.0.0","1.1.0","1.2.0","1.3.0"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jupyterhub-ltiauthenticator/PYSEC-2025-120.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}