JupyterGHSA-rcx2-m7jp-p9wj
Jupyter Notebook open redirect vulnerability
Medium6.1CVE-2019-10856 · Published Apr 9, 2019 · updated Sep 26, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| notebook PyPI | < 5.7.8 | 5.7.8 |
Details and references
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-601
- Also known as
- CVE-2019-10856, PYSEC-2019-158
- nvd.nist.gov/vuln/detail/CVE-2019-10856
- github.com/jupyter/notebook/commit/979e0bd15e794ceb00cc63737fcd5fd9addc4a99
- blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4
- github.com/jupyter/notebook
- github.com/jupyter/notebook/compare/16cf97c...b8e30ea
- github.com/pypa/advisory-database/tree/main/vulns/notebook/PYSEC-2019-158.yaml
More Jupyter advisories
All Jupyter| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 22019 | Open Redirect vulnerability in jupyterhub and notebook CVE-2019-10255Medium6.1fixed in 0.9.6, 5.7.8 | Medium6.1 | 0.9.6, 5.7.8 |
| Nov 212018 | Jupyter Notebook XSS via directory name CVE-2018-19352Medium6.1fixed in 5.7.2 | Medium6.1 | 5.7.2 |
| Nov 212018 | Jupyter Notebook XSS via untrusted notebooks CVE-2018-19351Medium6.1fixed in 5.7.1 | Medium6.1 | 5.7.1 |
| Nov 82019 | Cross-site scripting in Jupyter Notebook CVE-2018-21030Medium5.3fixed in 5.5.0rc1 | Medium5.3 | 5.5.0rc1 |
| Jul 122018 | Jupyter Notebook file bypasses sanitization, executes JavaScript CVE-2018-8768High7.8fixed in 5.4.1 | High7.8 | 5.4.1 |
| Nov 182020 | Open redirect in Jupyter Notebook CVE-2020-26215Low4.4fixed in 6.1.5 | Low4.4 | 6.1.5 |