Jupyter

Notebook

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 28.08.2024 20:15:07
  • Zuletzt bearbeitet 30.08.2024 15:56:16

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using...

  • EPSS 0.45%
  • Veröffentlicht 19.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:56:15

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. ...

  • EPSS 0.14%
  • Veröffentlicht 19.01.2024 21:15:09
  • Zuletzt bearbeitet 21.11.2024 08:56:15

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a th...

  • EPSS 0.52%
  • Veröffentlicht 14.06.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:46

Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidden directori...

  • EPSS 0.22%
  • Veröffentlicht 31.03.2022 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:51:01

The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header valu...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 09.08.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:45

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja byp...

  • EPSS 0.57%
  • Veröffentlicht 18.11.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 05:19:32

Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously cra...

  • EPSS 0.37%
  • Veröffentlicht 31.10.2019 15:15:10
  • Zuletzt bearbeitet 21.11.2024 04:02:44

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 04.04.2019 16:29:03
  • Zuletzt bearbeitet 21.11.2024 04:19:59

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

  • EPSS 0.49%
  • Veröffentlicht 28.03.2019 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:18:45

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Se...