6.1
CVSSv3

CVE-2019-10255

Published: 28/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

An Open Redirect vulnerability for all browsers in Jupyter Notebook prior to 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub prior to 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jupyter jupyterhub

jupyter notebook

Vendor Advisories

Several security issues were fixed in Jupyter Notebook ...
Debian Bug report logs - #924515 jupyter-notebook: CVE-2019-9644 Package: src:jupyter-notebook; Maintainer for src:jupyter-notebook is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 13 Mar 2019 20:45:01 UTC Severity: important ...
Debian Bug report logs - #925939 jupyter-notebook: CVE-2019-10255: open redirect vulnerability Package: src:jupyter-notebook; Maintainer for src:jupyter-notebook is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 28 Mar 2019 21: ...