NA

CVE-2023-39968

Published: 28/08/2023 Updated: 15/09/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been addressed in commit `29036259` which is included in release 2.7.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

jupyter jupyter server

Vendor Advisories

Debian Bug report logs - #1057739 jupyter-server: CVE-2023-39968 Package: src:jupyter-server; Maintainer for src:jupyter-server is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 7 Dec 2023 20:12:02 UTC Severity: important Tags: security, upstream ...