PT-2023-27180 · Unknown+1 · Jupyter Server+1
Davwwwx
·
Published
2023-08-28
·
Updated
2023-09-15
·
CVE-2023-39968
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
jupyter-server versions prior to 2.7.2
Description
The issue is an Open Redirect Vulnerability in jupyter-server, which is the backend for Jupyter web applications. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs.
Recommendations
To resolve the issue, upgrade to Jupyter Server 2.7.2.
As a temporary workaround, consider restricting access to the login functionality until the upgrade is applied.
There are no known workarounds for this vulnerability.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Jupyter Server