PT-2020-16361 · Project Jupyter · Jupyter Server

Zhuonan Li

·

Published

2020-11-24

·

Updated

2020-12-02

·

CVE-2020-26232

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jupyter Server versions prior to 1.0.6
Description The issue is an Open redirect vulnerability, where a maliciously crafted link to a Jupyter server could redirect the browser to a different website. All Jupyter servers are technically affected, but these maliciously crafted links can only be reasonably made for known Jupyter server hosts. A link to a Jupyter server may appear safe but ultimately redirect to a spoofed server on the public internet.
Recommendations For versions prior to 1.0.6, upgrade to Jupyter Server version 1.0.6 to resolve the issue. As a temporary workaround, consider avoiding the use of links to Jupyter servers from unknown or untrusted sources until the upgrade is applied.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26232
GHSA-GRFJ-WJV9-4F9V
OPENSUSE-SU-2024:11233-1
OPENSUSE-SU-2024:14143-1
PYSEC-2020-234

Affected Products

Jupyter Server