Impact
Back in Jupyter Server releases before 2.21.0, the 5xx request logging routine copied the entire Referer header into a JSON header block without removing any access token present in that URL. When a request that triggers a server error also includes a token-bearing Referer, the plain‑text token is written to the server logs. An individual who can read those logs therefore can recover the token and employ it to access the Jupyter Server with the affected user's permissions.
Affected Systems
The flaw affects the Jupyter Server (jupyter_server) product from any version older than 2.21.0. Any installation that remains on or before the pre‑2.21.0 releases is vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating moderate severity, and the EPSS score is below 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves steering the server to produce an HTTP 500 response while an attacker supplies a crafted Referer header containing a token. Crucially, the attacker must also be able to read the server logs, typically restricting practical exploitation to users with privileged or elevated log‑access rights. Consequently, while the risk is moderate, the impact can be significant if log visibility is not tightly controlled.
OpenCVE Enrichment
Github GHSA