CVE-2019-10255

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
References
Link Resource
https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4 Vendor Advisory
https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb Patch Third Party Advisory
https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b Patch Third Party Advisory
https://github.com/jupyter/notebook/commit/d65328d4841892b412aef9015165db1eb029a8ed Patch Third Party Advisory
https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/
https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4 Vendor Advisory
https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb Patch Third Party Advisory
https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b Patch Third Party Advisory
https://github.com/jupyter/notebook/commit/d65328d4841892b412aef9015165db1eb029a8ed Patch Third Party Advisory
https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jupyter:jupyterhub:*:*:*:*:*:*:*:*
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:18

Type Values Removed Values Added
References () https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4 - Vendor Advisory () https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4 - Vendor Advisory
References () https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb - Patch, Third Party Advisory () https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb - Patch, Third Party Advisory
References () https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b - Patch, Third Party Advisory () https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b - Patch, Third Party Advisory
References () https://github.com/jupyter/notebook/commit/d65328d4841892b412aef9015165db1eb029a8ed - Patch, Third Party Advisory () https://github.com/jupyter/notebook/commit/d65328d4841892b412aef9015165db1eb029a8ed - Patch, Third Party Advisory
References () https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c - Third Party Advisory, Patch () https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c - Patch, Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/ -

07 Nov 2023, 03:02

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/', 'name': 'FEDORA-2019-9e67979b2a', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/', 'name': 'FEDORA-2019-a6e1287e76', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/ -

Information

Published : 2019-03-28 16:29

Updated : 2024-11-21 04:18


NVD link : CVE-2019-10255

Mitre link : CVE-2019-10255

CVE.ORG link : CVE-2019-10255


JSON object : View

Products Affected

jupyter

  • jupyterhub
  • notebook
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')