Vulnerabilities > Jupyter > Low

DATE CVE VULNERABILITY TITLE RISK
2021-11-03 CVE-2021-41134 Cross-site Scripting vulnerability in Jupyter Nbdime and Nbdime-Jupyterlab
nbdime provides tools for diffing and merging of Jupyter Notebooks.
network
jupyter CWE-79
3.5
2021-01-13 CVE-2020-36191 Cross-Site Request Forgery (CSRF) vulnerability in Jupyter Jupyterhub 1.1.0
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
network
jupyter CWE-352
3.5
2020-12-01 CVE-2020-26250 Incorrect Authorization vulnerability in Jupyter Oauthenticator 0.12.0/0.12.1
OAuthenticator is an OAuth login mechanism for JupyterHub.
network
jupyter CWE-863
3.5