CVE-2019-10856Open Redirect in Notebook

CWE-601Open Redirect11 documents8 sources
Severity
6.1MEDIUMNVD
EPSS
0.2%
top 62.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 4
Latest updateAug 30

Description

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDjupyter/notebook< 5.7.8
PyPIjupyter/notebook< 5.7.8

Patches

🔴Vulnerability Details

5
OSV
jupyter-notebook vulnerabilities2022-08-30
OSV
Jupyter Notebook open redirect vulnerability2019-04-09
GHSA
Jupyter Notebook open redirect vulnerability2019-04-09
CVEList
CVE-2019-10856: In Jupyter Notebook before 52019-04-04
OSV
CVE-2019-10856: In Jupyter Notebook before 52019-04-04

📋Vendor Advisories

2
Ubuntu
Jupyter Notebook vulnerabilities2022-08-30
Debian
CVE-2019-10856: jupyter-notebook - In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc...2019

📄Research Papers

1
arXiv
Threat Assessment in Machine Learning based Systems2022-06-30

💬Community

2
Bugzilla
CVE-2019-10856 python-notebook: open redirect vulnerability by an empty netloc2019-04-05
Bugzilla
CVE-2019-10856 python-notebook: open redirect vulnerability by an empty netloc [fedora-all]2019-04-05
CVE-2019-10856 — Open Redirect in Jupyter Notebook | cvebase