PT-2023-7528 · Unknown+1 · Jupyter Server+1

Krsecu

·

Published

2023-12-04

·

Updated

2023-12-14

·

CVE-2023-49080

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jupyter Server versions prior to 2.11.2
Description The Jupyter Server has an issue related to unhandled errors in API requests coming from an authenticated user, which can include traceback information and path information. Since the requesting user already has arbitrary execution permissions in the same environment, the revealed paths are not considered particularly sensitive. There is no known mechanism to trigger these errors without authentication.
Recommendations For versions prior to 2.11.2, upgrade to version 2.11.2 or later, which includes a fix that no longer includes traceback information in JSON error responses. As a temporary workaround, consider restricting access to sensitive paths and information, but note that there are no known workarounds for this issue.

Exploit

Fix

Improper Access Control

Information Disclosure

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-08582
CVE-2023-49080
GHSA-H56G-GQ9V-VC8R
OPENSUSE-SU-2024:13489-1
PYSEC-2023-272

Affected Products

Debian
Jupyter Server