Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10255

Опубликовано: 28 мар. 2019
Источник: debian

Описание

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jupyter-notebookfixed5.7.8-1package
jupyter-notebookno-dsastretchpackage
jupyterhubnot-affectedpackage

Примечания

  • https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb

  • https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b

  • When adressing this issue make sure to not open CVE-2019-10856 and apply the

  • complete fix.

  • https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4

  • https://github.com/jupyter/notebook/commit/979e0bd15e794ceb00cc63737fcd5fd9addc4a99

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

CVSS3: 6.1
nvd
почти 7 лет назад

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

CVSS3: 6.1
github
почти 7 лет назад

Open Redirect vulnerability in jupyterhub and notebook