Vulnerabilities > CVE-2020-26232 - Unspecified vulnerability in Jupyter Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to a different website. All jupyter servers are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A link to your jupyter server may appear safe, but ultimately redirect to a spoofed server on the public internet.
Vulnerable Configurations
References
- https://github.com/jupyter/jupyter_server/security/advisories/GHSA-grfj-wjv9-4f9v
- https://github.com/jupyter/jupyter_server/security/advisories/GHSA-grfj-wjv9-4f9v
- https://github.com/jupyter-server/jupyter_server/blob/master/CHANGELOG.md#106---2020-11-18
- https://github.com/jupyter-server/jupyter_server/blob/master/CHANGELOG.md#106---2020-11-18
- https://github.com/jupyter-server/jupyter_server/commit/3d83e49090289c431da253e2bdb8dc479cbcb157
- https://github.com/jupyter-server/jupyter_server/commit/3d83e49090289c431da253e2bdb8dc479cbcb157