CVE-2024-28233
published 2024-03-27CVE-2024-28233: JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS…
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.33%
25.4th percentile
JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve full access to JupyterHub API and user's single-user server. The affected configurations are single-origin JupyterHub deployments and JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server. This vulnerability is fixed in 4.1.0.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyterhub | < jupyterhub 5.0.0+ds1-1 (forky) | jupyterhub 5.0.0+ds1-1 (forky) |
| jupyter | jupyterhub | < 4.1.0 | 4.1.0 |
| jupyterhub | jupyterhub | < 4.1.0 | 4.1.0 |
| jupyterhub | jupyterhub | >= 0 < 5.0.0+ds1-1 | 5.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 5.0.0+ds1-1 | 5.0.0+ds1-1 |
| jupyterhub | jupyterhub | >= 0 < 4.1.0 | 4.1.0 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
ghsa·2024-03-28
CVE-2024-28233 [HIGH] CWE-352 Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
### Impact
Affected configurations:
- Single-origin JupyterHub deployments
- JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server.
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
- Full access to JupyterHub API and user's single-user server, e.g.
- Create and exfiltrate an API Token
- Exfiltrate all files hosted on the user's single-user server: notebooks, images, etc.
- Install malicious extensions. They can be used as a backdoor to silently regain access
OSV
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
osv·2024-03-28
CVE-2024-28233 [HIGH] Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
### Impact
Affected configurations:
- Single-origin JupyterHub deployments
- JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server.
By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following:
- Full access to JupyterHub API and user's single-user server, e.g.
- Create and exfiltrate an API Token
- Exfiltrate all files hosted on the user's single-user server: notebooks, images, etc.
- Install malicious extensions. They can be used as a backdoor to silently regain access
OSV
CVE-2024-28233: JupyterHub is an open source multi-user server for Jupyter notebooks
osv·2024-03-27·CVSS 6.1
CVE-2024-28233 [MEDIUM] CVE-2024-28233: JupyterHub is an open source multi-user server for Jupyter notebooks
JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve full access to JupyterHub API and user's single-user server. The affected configurations are single-origin JupyterHub deployments and JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server. This vulnerability is fixed in 4.1.0.
Debian
CVE-2024-28233: jupyterhub - JupyterHub is an open source multi-user server for Jupyter notebooks. By trickin...
vendor_debian·2024·CVSS 8.1
CVE-2024-28233 [HIGH] CVE-2024-28233: jupyterhub - JupyterHub is an open source multi-user server for Jupyter notebooks. By trickin...
JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve full access to JupyterHub API and user's single-user server. The affected configurations are single-origin JupyterHub deployments and JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server. This vulnerability is fixed in 4.1.0.
Scope: local
bookworm: open
forky: resolved (fixed in 5.0.0+ds1-1)
sid: resolved (fixed in 5.0.0+ds1-1)
trixie: resolved (fixed in 5.0.0+ds1-1)
No detection rules found.
No public exploits indexed.
https://github.com/jupyterhub/jupyterhub/commit/e2798a088f5ad45340fe79cdf1386198e664f77fhttps://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-7r3h-4ph8-w38ghttps://github.com/jupyterhub/jupyterhub/commit/e2798a088f5ad45340fe79cdf1386198e664f77fhttps://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-7r3h-4ph8-w38g
2024-03-27
Published