PT-2019-11663 · Project Jupyter+4 · Jupyter Notebook+5
Published
2019-03-28
·
Updated
2022-09-10
·
CVE-2019-10255
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Jupyter Notebook versions prior to 5.7.7
JupyterHub versions prior to 0.9.5
Description:
The issue allows crafted links to the login page to redirect to a malicious site after successful login. This affects all browsers in Jupyter Notebook and some browsers, such as Chrome and Firefox, in JupyterHub. Servers running on a base url prefix are not affected.
Recommendations:
For Jupyter Notebook versions prior to 5.7.7, update to version 5.7.7 or later.
For JupyterHub versions prior to 0.9.5, update to version 0.9.5 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Firefox
Jupyter Notebook
Jupyterhub
Linuxmint
Ubuntu