PT-2023-27180 · Unknown+1 · Jupyter Server+1

Davwwwx

·

Published

2023-08-28

·

Updated

2023-09-15

·

CVE-2023-39968

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions jupyter-server versions prior to 2.7.2
Description The issue is an Open Redirect Vulnerability in jupyter-server, which is the backend for Jupyter web applications. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs.
Recommendations To resolve the issue, upgrade to Jupyter Server 2.7.2. As a temporary workaround, consider restricting access to the login functionality until the upgrade is applied. There are no known workarounds for this vulnerability.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2023-39968
GHSA-R726-VMFQ-J9J3
OPENSUSE-SU-2024:13260-1
PYSEC-2023-155

Affected Products

Debian
Jupyter Server