Impact user API tokens issued to single-user servers are specified in the environment of systemd units, which are accessible to all users.
In particular, the-littlest-jupyterhub is affected, which uses systemdspawner by default.
Patches Patched in jupyterhub-systemdspawner v0.15
Workarounds No workaround other than upgrading systemdspawner to 0.15
For more information
If you have any questions or comments about this advisory: Open a thread in the Jupyter forum Email us at security@ipython.org