PT-2022-15049 · Unknown · Jupyter Server Proxy
Mr-R3Bot
·
Published
2022-01-25
·
Updated
2022-02-01
·
CVE-2022-21697
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Jupyter Server Proxy versions prior to 3.2.1
Description
The issue is related to Server-Side Request Forgery (SSRF) due to a lack of input validation, allowing authenticated clients to proxy requests to other hosts and bypass the
allowed hosts check. This is considered low to moderate severity because authentication is required, which already grants permissions to make the same requests via kernel or terminal execution. Any user deploying Jupyter Server or Notebook with the jupyter-proxy-server extension enabled is affected.Recommendations
For versions prior to 3.2.1, upgrade to version 3.2.1 to receive a patch.
As a temporary workaround, users can also install the patch manually.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyter Server Proxy