Skip to content
JupyterGHSA-hrw6-wg82-cm62

Jupyter server on Windows discloses Windows user password hash

High7.5CVE-2024-35178 · Published Jun 6, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyter-server
PyPI
< 2.14.12.14.1
Details and references

### Summary Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this password to gain access to the Windows machine hosting the Jupyter server, or access other network-accessible machines or 3rd party services using that credential. Or an attacker perform an NTLM relay attack without cracking the credential to gain access to other network-accessible machines.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200
Also known as
CVE-2024-35178, PYSEC-2024-165

More Jupyter advisories

All Jupyter
DateAdvisory
Jul 162024JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template
CVE-2024-39700Critical9.8fixed in 4.3.0
Aug 82024JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2024-41942High7.2fixed in 4.1.6, 5.1.0
Mar 282024Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
CVE-2024-28233High8.1fixed in 4.1.0
Aug 292024HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2024-43805High7.6fixed in 3.6.8, 4.2.5, 7.2.2
Jan 192024JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2024-22421High7.6fixed in 3.6.7, 4.0.11, 7.0.7
Jan 192024JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2024-22420Medium6.5fixed in 4.0.11, 7.0.7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.