Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may appear safe, but ultimately redirect to a spoofed server on the public internet. The issue is patched in version 6.1.5.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jupyter-notebook | Dec 3, 2020 | Nov 18, 2020 |
| Suse | — | Upgrade jupyter-notebook-latexUpgrade python3-notebook-langUpgrade jupyter-notebook-langUpgrade python2-jupyter_notebook-latexUpgrade python2-jupyter_notebookUpgrade python2-notebookUpgrade jupyter-notebook-docUpgrade python3-jupyter_notebook-langUpgrade python3-jupyter_notebookUpgrade python-jupyter_notebook-docUpgrade python3-notebookUpgrade python2-notebook-langUpgrade python2-jupyter_notebook-langUpgrade jupyter-notebookUpgrade python3-jupyter_notebook-latex | Jan 8, 2021 | Nov 18, 2020 |
| Ubuntu | — | Upgrade python3-notebookUpgrade jupyter-notebookUpgrade python-notebook | Aug 31, 2022 | Nov 18, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub