PT-2019-11663 · Project Jupyter+4 · Jupyter Notebook+5

Published

2019-03-28

·

Updated

2022-09-10

·

CVE-2019-10255

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Jupyter Notebook versions prior to 5.7.7 JupyterHub versions prior to 0.9.5
Description: The issue allows crafted links to the login page to redirect to a malicious site after successful login. This affects all browsers in Jupyter Notebook and some browsers, such as Chrome and Firefox, in JupyterHub. Servers running on a base url prefix are not affected.
Recommendations: For Jupyter Notebook versions prior to 5.7.7, update to version 5.7.7 or later. For JupyterHub versions prior to 0.9.5, update to version 0.9.5 or later.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2019-10255
GHSA-RV62-4PMJ-XW6H
MGASA-2022-0323
OPENSUSE-SU-2024:11242-1
USN-5585-1

Affected Products

Google Chrome
Firefox
Jupyter Notebook
Jupyterhub
Linuxmint
Ubuntu