An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4 - Vendor Advisory | |
References | () https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb - Patch, Third Party Advisory | |
References | () https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b - Patch, Third Party Advisory | |
References | () https://github.com/jupyter/notebook/commit/d65328d4841892b412aef9015165db1eb029a8ed - Patch, Third Party Advisory | |
References | () https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c - Patch, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/ - |
07 Nov 2023, 03:02
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-03-28 16:29
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10255
Mitre link : CVE-2019-10255
CVE.ORG link : CVE-2019-10255
JSON object : View
Products Affected
jupyter
- jupyterhub
- notebook
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')