CVE-2019-10255Open Redirect in Jupyterhub

CWE-601Open Redirect18 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.5%
top 35.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateJul 21

Description

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDjupyter/notebook< 5.7.7+1
PyPIjupyter/notebook< 5.7.8
NVDjupyter/jupyterhub< 0.9.5
PyPIjupyterhub/jupyterhub< 0.9.6

Patches

🔴Vulnerability Details

9
OSV
jupyter-notebook vulnerabilities2022-08-30
OSV
Jupyter Notebook open redirect vulnerability2019-04-09
GHSA
Jupyter Notebook open redirect vulnerability2019-04-09
CVEList
CVE-2019-10856: In Jupyter Notebook before 52019-04-04
OSV
CVE-2019-10856: In Jupyter Notebook before 52019-04-04

📋Vendor Advisories

3
Ubuntu
Jupyter Notebook vulnerabilities2022-08-30
Debian
CVE-2019-10856: jupyter-notebook - In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc...2019
Debian
CVE-2019-10255: jupyter-notebook - An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7...2019

📄Research Papers

1
arXiv
Exploring Security Commits in Python2023-07-21

💬Community

3
Bugzilla
CVE-2019-10856 python-notebook: open redirect vulnerability by an empty netloc2019-04-05
Bugzilla
CVE-2019-10255 python-notebook: Open redirect vulnerability in the login page [fedora-all]2019-03-30
Bugzilla
CVE-2019-10255 python-notebook: Open redirect vulnerability in the login page2019-03-30
CVE-2019-10255 — Open Redirect in Jupyter Jupyterhub | cvebase