CVE-2022-24758
published 2022-03-31CVE-2022-24758: The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.08%
61.8th percentile
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server. Jupyter notebook version 6.4.x contains a patch for this issue. There are currently no known workarounds.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyter-notebook | < jupyter-notebook 6.4.12-1 (bookworm) | jupyter-notebook 6.4.12-1 (bookworm) |
| jupyter | notebook | < 6.4.10 | 6.4.10 |
| jupyter | notebook | >= 0 < 6.4.10 | 6.4.10 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Jupyter Notebook vulnerabilities
vendor_ubuntu·2022-08-30·CVSS 6.1
CVE-2022-24758 [MEDIUM] Jupyter Notebook vulnerabilities
Title: Jupyter Notebook vulnerabilities
Summary: Several security issues were fixed in Jupyter Notebook.
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)
It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)
It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect
Debian
CVE-2022-24758: jupyter-notebook - The Jupyter notebook is a web-based notebook environment for interactive computi...
vendor_debian·2022·CVSS 7.5
CVE-2022-24758 [HIGH] CVE-2022-24758: jupyter-notebook - The Jupyter notebook is a web-based notebook environment for interactive computi...
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server. Jupyter notebook version 6.4.x contains a patch for this issue. There are currently no known workarounds.
Scope: local
bookworm: resolved (fixed in 6.4.12-1)
bullseye: open
forky: resolved (fixed in 6.4.12-1)
sid: resolved (fixed in 6.4.12-1)
trixie: resolved (fixed in 6.4.12-1)
OSV
jupyter-notebook vulnerabilities
osv·2022-08-30·CVSS 6.1
CVE-2018-19351 [MEDIUM] jupyter-notebook vulnerabilities
jupyter-notebook vulnerabilities
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)
It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)
It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-10255)
It w
OSV
Sensitive Auth & Cookie data stored in Jupyter server logs
osv·2022-04-05
CVE-2022-24758 [HIGH] Sensitive Auth & Cookie data stored in Jupyter server logs
Sensitive Auth & Cookie data stored in Jupyter server logs
Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server.
Upgrade to notebook version 6.4.10
### For more information
If you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list [[email protected]](mailto:[email protected]).
Credit: @3coins for reporting. Thank you!
GHSA
Sensitive Auth & Cookie data stored in Jupyter server logs
ghsa·2022-04-05
CVE-2022-24758 [HIGH] CWE-532 Sensitive Auth & Cookie data stored in Jupyter server logs
Sensitive Auth & Cookie data stored in Jupyter server logs
Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server.
Upgrade to notebook version 6.4.10
### For more information
If you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list [[email protected]](mailto:[email protected]).
Credit: @3coins for reporting. Thank you!
OSV
CVE-2022-24758: The Jupyter notebook is a web-based notebook environment for interactive computing
osv·2022-03-31·CVSS 7.5
CVE-2022-24758 [HIGH] CVE-2022-24758: The Jupyter notebook is a web-based notebook environment for interactive computing
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server. Jupyter notebook version 6.4.x contains a patch for this issue. There are currently no known workarounds.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-31
Published