CVE-2020-26215
published 2020-11-18CVE-2020-26215: Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.21%
65.1th percentile
Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may appear safe, but ultimately redirect to a spoofed server on the public internet. The issue is patched in version 6.1.5.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | jupyter-notebook | < jupyter-notebook 6.1.5-1 (bookworm) | jupyter-notebook 6.1.5-1 (bookworm) |
| jupyter | notebook | < 6.1.5 | 6.1.5 |
| jupyter | notebook | >= 0 < 6.1.5 | 6.1.5 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Jupyter Notebook vulnerabilities
vendor_ubuntu·2022-08-30·CVSS 6.1
CVE-2022-24758 [MEDIUM] Jupyter Notebook vulnerabilities
Title: Jupyter Notebook vulnerabilities
Summary: Several security issues were fixed in Jupyter Notebook.
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)
It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)
It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect
Debian
CVE-2020-26215: jupyter-notebook - Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A mali...
vendor_debian·2020·CVSS 4.4
CVE-2020-26215 [MEDIUM] CVE-2020-26215: jupyter-notebook - Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A mali...
Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may appear safe, but ultimately redirect to a spoofed server on the public internet. The issue is patched in version 6.1.5.
Scope: local
bookworm: resolved (fixed in 6.1.5-1)
bullseye: resolved (fixed in 6.1.5-1)
forky: resolved (fixed in 6.1.5-1)
sid: resolved (fixed in 6.1.5-1)
trixie: resolved (fixed in 6.1.5-1)
OSV
jupyter-notebook vulnerabilities
osv·2022-08-30·CVSS 6.1
CVE-2018-19351 [MEDIUM] jupyter-notebook vulnerabilities
jupyter-notebook vulnerabilities
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)
It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)
It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-10255)
It w
OSV
Open redirect in Jupyter Notebook
osv·2020-11-18
CVE-2020-26215 [LOW] Open redirect in Jupyter Notebook
Open redirect in Jupyter Notebook
### Impact
_What kind of vulnerability is it? Who is impacted?_
Open redirect vulnerability - a maliciously crafted link to a notebook server could redirect the browser to a different website.
All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may *appear* safe, but ultimately redirect to a spoofed server on the public internet.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
Patched in notebook 6.1.5
### References
[OWASP page on open redirects](https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html)
### For more information
If you have any
OSV
CVE-2020-26215: Jupyter Notebook before version 6
osv·2020-11-18·CVSS 6.1
CVE-2020-26215 [MEDIUM] CVE-2020-26215: Jupyter Notebook before version 6
Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may appear safe, but ultimately redirect to a spoofed server on the public internet. The issue is patched in version 6.1.5.
GHSA
Open redirect in Jupyter Notebook
ghsa·2020-11-18
CVE-2020-26215 [LOW] CWE-601 Open redirect in Jupyter Notebook
Open redirect in Jupyter Notebook
### Impact
_What kind of vulnerability is it? Who is impacted?_
Open redirect vulnerability - a maliciously crafted link to a notebook server could redirect the browser to a different website.
All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may *appear* safe, but ultimately redirect to a spoofed server on the public internet.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
Patched in notebook 6.1.5
### References
[OWASP page on open redirects](https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html)
### For more information
If you have any
No detection rules found.
No public exploits indexed.
https://github.com/jupyter/notebook/commit/3cec4bbe21756de9f0c4bccf18cf61d840314d74https://github.com/jupyter/notebook/security/advisories/GHSA-c7vm-f5p4-8fqhhttps://lists.debian.org/debian-lts-announce/2020/12/msg00004.htmlhttps://github.com/jupyter/notebook/commit/3cec4bbe21756de9f0c4bccf18cf61d840314d74https://github.com/jupyter/notebook/security/advisories/GHSA-c7vm-f5p4-8fqhhttps://lists.debian.org/debian-lts-announce/2020/12/msg00004.html
2020-11-18
Published