CVE-2024-22421
published 2024-01-19CVE-2024-22421: JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who…
PriorityP334medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.66%
47.6th percentile
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyterlab | < jupyterlab 4.0.11+ds1-1 (forky) | jupyterlab 4.0.11+ds1-1 (forky) |
| fedoraproject | fedora | — | — |
| jupyter | jupyterlab | < 3.6.7 | 3.6.7 |
| jupyter | jupyterlab | >= 4.0.0 < 4.0.11 | 4.0.11 |
| jupyter | notebook | >= 7.0.0 < 7.0.7 | 7.0.7 |
| jupyter | notebook | >= 7.0.0 < 7.0.7 | 7.0.7 |
| jupyterlab | jupyterlab | < 3.6.7 | 3.6.7 |
| jupyterlab | jupyterlab | — | — |
| jupyterlab | jupyterlab | >= 0 < 4.0.11+ds1-1 | 4.0.11+ds1-1 |
| jupyterlab | jupyterlab | >= 0 < 4.0.11+ds1-1 | 4.0.11+ds1-1 |
| jupyterlab | jupyterlab | >= 0 < 3.6.7 | 3.6.7 |
| jupyterlab | jupyterlab | >= 4.0.0 < 4.0.11 | 4.0.11 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
JupyterLab vulnerable to potential authentication and CSRF tokens leak
osv·2024-01-19
CVE-2024-22421 [HIGH] JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab vulnerable to potential authentication and CSRF tokens leak
### Impact
Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version.
### Patches
JupyterLab 4.1.0b2, 4.0.11, and 3.6.7 were patched.
### Workarounds
No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
### References
Vulnerability reported by user @davwwwx via the [bug bounty program](https://app.intigriti.com/programs/jupyter/jupyter/detail) [sponsored by the European Commission](https://commission.europa.eu/news/european-commissions-open-source-programme-office-starts-bug-bounties-2022-01-1
GHSA
JupyterLab vulnerable to potential authentication and CSRF tokens leak
ghsa·2024-01-19
CVE-2024-22421 [HIGH] CWE-200 JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab vulnerable to potential authentication and CSRF tokens leak
### Impact
Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version.
### Patches
JupyterLab 4.1.0b2, 4.0.11, and 3.6.7 were patched.
### Workarounds
No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
### References
Vulnerability reported by user @davwwwx via the [bug bounty program](https://app.intigriti.com/programs/jupyter/jupyter/detail) [sponsored by the European Commission](https://commission.europa.eu/news/european-commissions-open-source-programme-office-starts-bug-bounties-2022-01-1
OSV
CVE-2024-22421: JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture
osv·2024-01-19·CVSS 6.5
CVE-2024-22421 [MEDIUM] CVE-2024-22421: JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
Debian
CVE-2024-22421: jupyterlab - JupyterLab is an extensible environment for interactive and reproducible computi...
vendor_debian·2024·CVSS 7.6
CVE-2024-22421 [HIGH] CVE-2024-22421: jupyterlab - JupyterLab is an extensible environment for interactive and reproducible computi...
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
Scope: local
forky: resolved (fixed in 4.0.11+ds1-1)
sid: resolved (fixed in 4.0.11+ds1-1)
trixie: resolved (fixed in 4.0.11+ds1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jupyterlab/jupyterlab/commit/19bd9b96cb2e77170a67e43121637d0b5619e8c6https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-44cc-43rp-5947https://lists.fedoraproject.org/archives/list/[email protected]/message/UQJKNRDRFMKGVRIYNNN6CKMNJDNYWO2H/https://github.com/jupyterlab/jupyterlab/commit/19bd9b96cb2e77170a67e43121637d0b5619e8c6https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-44cc-43rp-5947https://lists.fedoraproject.org/archives/list/[email protected]/message/UQJKNRDRFMKGVRIYNNN6CKMNJDNYWO2H/
2024-01-19
Published