PT-2022-15049 · Unknown · Jupyter Server Proxy

Mr-R3Bot

·

Published

2022-01-25

·

Updated

2022-02-01

·

CVE-2022-21697

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jupyter Server Proxy versions prior to 3.2.1
Description The issue is related to Server-Side Request Forgery (SSRF) due to a lack of input validation, allowing authenticated clients to proxy requests to other hosts and bypass the allowed hosts check. This is considered low to moderate severity because authentication is required, which already grants permissions to make the same requests via kernel or terminal execution. Any user deploying Jupyter Server or Notebook with the jupyter-proxy-server extension enabled is affected.
Recommendations For versions prior to 3.2.1, upgrade to version 3.2.1 to receive a patch. As a temporary workaround, users can also install the patch manually.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21697
GHSA-GCV9-6737-PJQW
PYSEC-2022-16

Affected Products

Jupyter Server Proxy