Jupyter

Notebook

16 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Published 28.08.2024 20:15:07
  • Last modified 30.08.2024 15:56:16

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using...

  • EPSS 0.45%
  • Published 19.01.2024 21:15:09
  • Last modified 21.11.2024 08:56:15

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. ...

  • EPSS 0.14%
  • Published 19.01.2024 21:15:09
  • Last modified 21.11.2024 08:56:15

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a th...

  • EPSS 0.52%
  • Published 14.06.2022 18:15:08
  • Last modified 21.11.2024 06:58:46

Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidden directori...

  • EPSS 0.22%
  • Published 31.03.2022 23:15:07
  • Last modified 21.11.2024 06:51:01

The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header valu...

Exploit
  • EPSS 0.23%
  • Published 09.08.2021 21:15:08
  • Last modified 21.11.2024 06:07:45

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja byp...

  • EPSS 0.57%
  • Published 18.11.2020 22:15:11
  • Last modified 21.11.2024 05:19:32

Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously cra...

  • EPSS 0.37%
  • Published 31.10.2019 15:15:10
  • Last modified 21.11.2024 04:02:44

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

Exploit
  • EPSS 0.16%
  • Published 04.04.2019 16:29:03
  • Last modified 21.11.2024 04:19:59

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

  • EPSS 0.49%
  • Published 28.03.2019 16:29:00
  • Last modified 21.11.2024 04:18:45

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Se...