CVE-2021-41247
published 2021-11-04CVE-2021-41247: JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.78%
52.3th percentile
JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place. Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment. The only workaround is to make sure that only one JupyterLab tab is open when you log out.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyterhub | < jupyterhub 2.0.0+ds1-1 (bookworm) | jupyterhub 2.0.0+ds1-1 (bookworm) |
| jupyter | jupyterhub | >= 1.0.0 < 1.5.0 | 1.5.0 |
| jupyterhub | jupyterhub | < 1.2.0 - jupyterhub (helm) | 1.2.0 - jupyterhub (helm) |
| jupyterhub | jupyterhub | — | — |
| jupyterhub | jupyterhub | >= 0 < 2.0.0+ds1-1 | 2.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 2.0.0+ds1-1 | 2.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 2.0.0+ds1-1 | 2.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 1.0.0 < 1.5.0 | 1.5.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
incomplete JupyterHub logout with simultaneous JupyterLab sessions
ghsa·2021-11-08
CVE-2021-41247 [MEDIUM] CWE-613 incomplete JupyterHub logout with simultaneous JupyterLab sessions
incomplete JupyterHub logout with simultaneous JupyterLab sessions
### Impact
Users of JupyterLab with JupyterHub who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place.
### Patches
Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment.
### Workarounds
The only workaround is to make sure that only one JupyterLab tab is open when you log out.
OSV
incomplete JupyterHub logout with simultaneous JupyterLab sessions
osv·2021-11-08
CVE-2021-41247 [MEDIUM] incomplete JupyterHub logout with simultaneous JupyterLab sessions
incomplete JupyterHub logout with simultaneous JupyterLab sessions
### Impact
Users of JupyterLab with JupyterHub who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place.
### Patches
Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment.
### Workarounds
The only workaround is to make sure that only one JupyterLab tab is open when you log out.
OSV
CVE-2021-41247: JupyterHub is an open source multi-user server for Jupyter notebooks
osv·2021-11-04·CVSS 7.5
CVE-2021-41247 [HIGH] CVE-2021-41247: JupyterHub is an open source multi-user server for Jupyter notebooks
JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place. Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment. The only workaround is to make sure that only one JupyterLab tab is open when you log out.
Debian
CVE-2021-41247: jupyterhub - JupyterHub is an open source multi-user server for Jupyter notebooks. In affecte...
vendor_debian·2021·CVSS 3.5
CVE-2021-41247 [LOW] CVE-2021-41247: jupyterhub - JupyterHub is an open source multi-user server for Jupyter notebooks. In affecte...
JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place. Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment. The only workaround is to make sure that only one JupyterLab tab is open when you log out.
Scope: local
bookworm: resolved (fixed in 2.0.0+ds1-1)
forky: resolved (fixed in 2.0.0+ds1-1)
sid: resolved (fixed in 2.0.0+ds1-1)
trixie: resolve
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-33709 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.5
CVE-2026-33709 [MEDIUM] CVE-2026-33709 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33709 :
JupyterHub vulnerability analysis and mitigation
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to version 5.4.4, an open redirect vulnerability in JupyterHub allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this. This issue has been patched in version 5.4.4.
Source : NVD
## 5.1
Score
Published April 3, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
JupyterHub
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPS
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
https://github.com/jupyterhub/jupyterhub/commit/5ac9e7f73a6e1020ffddc40321fc53336829fe27https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-cw7p-q79f-m2v7https://github.com/jupyterhub/jupyterhub/commit/5ac9e7f73a6e1020ffddc40321fc53336829fe27https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-cw7p-q79f-m2v7
2021-11-04
Published