Описание
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating system level), and with jupyter-server instances exposed to non-trusted network are vulnerable to unauthorised access and modification of file system beyond the jupyter root directory. This issue has been patched in version 2.2.2 and all users are advised to upgrade. Users unable to upgrade should uninstall jupyter-lsp.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.2 (исключая)
cpe:2.3:a:jupyter:language_server_protocol_integration:*:*:*:*:*:jupyter:*:*
EPSS
Процентиль: 38%
0.00167
Низкий
7.3 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-23
CWE-22
Связанные уязвимости
CVSS3: 7.3
github
около 2 лет назад
Unsecured endpoints in the jupyter-lsp server extension
EPSS
Процентиль: 38%
0.00167
Низкий
7.3 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-23
CWE-22