NA
CVSSv3

CVE-2025-32428

CVSSv4: 9 | CVSSv3: NA | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00032 | KEV: Not Included
Published: 15/04/2025 Updated: 15/04/2025

Vulnerability Summary

Remote Desktop Proxy Vulnerability in Jupyter Remote Desktop Proxy 3.0.0

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jupyterhub jupyter-remote-desktop-proxy