Description
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been addressed in commit `29036259` which is included in release 2.7.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0102 | jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been addressed in commit `29036259` which is included in release 2.7.2. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-r726-vmfq-j9j3 | Open Redirect Vulnerability in jupyter-server |
References
History
Mon, 30 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:03:19.337Z
Reserved: 2023-08-07T16:27:27.077Z
Link: CVE-2023-39968
Updated: 2024-08-02T18:18:10.086Z
Status : Modified
Published: 2023-08-28T21:15:07.777
Modified: 2024-11-21T08:16:08.627
Link: CVE-2023-39968
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA