Junglewise Threat Intelligence

CVE-2024-37300: PYSEC-2026-1711 - Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

CVE-2024-37300 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: oauthenticator (PyPI). Vendors: PyPI.

Executive brief

Globus `identity_provider` restriction ignored when used with `allow_all` in JupyterHub 5.0

Affected products

  • PyPI oauthenticator

Related threats