Severity
6.1MEDIUMNVD
CNA8.1
EPSS
0.1%
top 70.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 27
Latest updateMar 28

Description

JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve full access to JupyterHub API and user's single-user server. The affected configurations are single-origin JupyterHub deployments and JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDjupyter/jupyterhub< 4.1.0
CVEListV5jupyterhub/jupyterhub< 4.1.0
PyPIjupyterhub/jupyterhub< 4.1.0
Debianjupyterhub/jupyterhub< 5.0.0+ds1-1+1

Patches

🔴Vulnerability Details

4
GHSA
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing2024-03-28
OSV
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing2024-03-28
CVEList
XSS in JupyterHub via Self-XSS leveraged by Cookie Tossing2024-03-27
OSV
CVE-2024-28233: JupyterHub is an open source multi-user server for Jupyter notebooks2024-03-27

📋Vendor Advisories

1
Debian
CVE-2024-28233: jupyterhub - JupyterHub is an open source multi-user server for Jupyter notebooks. By trickin...2024

🕵️Threat Intelligence

1
Wiz
CVE-2026-33709 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2024-28233 — Cross-site Scripting in Jupyterhub | cvebase