Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22421

Опубликовано: 19 янв. 2024
Источник: nvd
CVSS3: 7.6
CVSS3: 6.5
EPSS Низкий

Описание

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their Authorization and XSRFToken tokens exposed to a third party when running an older jupyter-server version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade jupyter-server to version 2.7.2 or newer which includes a redirect vulnerability fix.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*
Версия до 3.6.7 (исключая)
cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.11 (исключая)
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.7 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00138
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 7.6
ubuntu
около 2 лет назад

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.

CVSS3: 7.6
debian
около 2 лет назад

JupyterLab is an extensible environment for interactive and reproducib ...

CVSS3: 7.6
github
около 2 лет назад

JupyterLab vulnerable to potential authentication and CSRF tokens leak

EPSS

Процентиль: 34%
0.00138
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-23