PT-2023-27180 · Unknown+1 · Jupyter Server+1

Davwwwx

·

Publicado

2023-08-28

·

Atualizado

2023-09-15

·

CVE-2023-39968

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jupyter-server versions prior to 2.7.2
Description The issue is an Open Redirect Vulnerability in jupyter-server, which is the backend for Jupyter web applications. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs.
Recommendations To resolve the issue, upgrade to Jupyter Server 2.7.2. As a temporary workaround, consider restricting access to the login functionality until the upgrade is applied. There are no known workarounds for this vulnerability.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39968
GHSA-R726-VMFQ-J9J3
OPENSUSE-SU-2024:13260-1
PYSEC-2023-155

Produtos afetados

Debian
Jupyter Server