Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2025-61669

4 месяца назад

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2025-61669

4 месяца назад

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-61669

4 месяца назад

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-61669

4 месяца назад

Jupyter Server is the backend for Jupyter web applications. In jupyter ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-qh7q-6qm3-653w

4 месяца назад

Jupyter Server has an open redirection vulnerability in `next` query parameter

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-61669

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

CVSS3: 6.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-61669

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

CVSS3: 6.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-61669

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

CVSS3: 6.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-61669

Jupyter Server is the backend for Jupyter web applications. In jupyter ...

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-qh7q-6qm3-653w

Jupyter Server has an open redirection vulnerability in `next` query parameter

0%
Низкий
4 месяца назад

Уязвимостей на страницу