Vulnerabilities > Jupyter

DATE CVE VULNERABILITY TITLE RISK
2024-01-19 CVE-2024-22420 Cross-site Scripting vulnerability in multiple products
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture.
network
low complexity
jupyter fedoraproject CWE-79
6.1
2024-01-19 CVE-2024-22421 Relative Path Traversal vulnerability in multiple products
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture.
network
low complexity
jupyter fedoraproject CWE-23
6.5
2024-01-18 CVE-2024-22415 Path Traversal vulnerability in Jupyter Language Server Protocol Integration
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol.
network
low complexity
jupyter CWE-22
critical
9.8
2023-12-08 CVE-2023-48311 Unspecified vulnerability in Jupyter Dockerspawner
dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers.
network
low complexity
jupyter
4.3
2023-12-04 CVE-2023-49080 Information Exposure Through an Error Message vulnerability in Jupyter Server
The Jupyter Server provides the backend (i.e.
network
low complexity
jupyter CWE-209
4.3
2023-08-28 CVE-2023-39968 Open Redirect vulnerability in Jupyter Server
jupyter-server is the backend for Jupyter web applications.
network
low complexity
jupyter CWE-601
6.1
2023-08-28 CVE-2023-40170 Missing Authentication for Critical Function vulnerability in Jupyter Server
jupyter-server is the backend for Jupyter web applications.
network
low complexity
jupyter CWE-306
6.1
2022-10-26 CVE-2022-39286 Uncontrolled Search Path Element vulnerability in multiple products
Jupyter Core is a package for the core common functionality of Jupyter projects.
network
low complexity
jupyter debian fedoraproject CWE-427
8.8
2022-08-18 CVE-2021-32862 Cross-site Scripting vulnerability in multiple products
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert.
network
low complexity
jupyter debian CWE-79
5.4
2022-06-14 CVE-2022-29241 Unspecified vulnerability in Jupyter Server
Jupyter Server provides the backend (i.e.
network
low complexity
jupyter
critical
9.0