Linux Distros Unpatched Vulnerability : CVE-2020-36191
Discription

image
The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account). (CVE-2020-36191) Note that Nessus relies on the presence of the package as reported by the vendor. File data…Read More

Back to Main

Subscribe for the latest news: